High severity7.5NVD Advisory· Published Sep 30, 2026· Updated Sep 30, 2026
CVE-2026-103471
CVE-2026-103471
Description
restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated attackers to exhaust server memory. Attackers can open TCP connections and stream bytes indefinitely without sending the header delimiter, forcing the server to allocate unbounded heap memory until the process is killed.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/Corvusoft/restbed/blob/e1227a297ce6d4e9f78222456507b29bb8ab77e9/src/corvusoft/restbed/detail/service_impl.cppnvd
- github.com/Corvusoft/restbed/blob/e1227a297ce6d4e9f78222456507b29bb8ab77e9/src/corvusoft/restbed/session.cppnvd
- github.com/Corvusoft/restbed/issues/558nvd
- www.vulncheck.com/advisories/restbed-through-5.0.0-denial-of-service-via-unbounded-header-bufferingnvd
News mentions
0No linked articles in our index yet.