CVE-2024-27316
published 2024-04-04CVE-2024-27316: HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not…
PriorityP359high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
91.33%
99.8th percentile
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.4.17 < 2.4.59 | 2.4.59 |
| apache | httpd | — | — |
| apache_software_foundation | apache_http_server | 2.4.17 – 2.4.58 | — |
| apple | macos_sonoma | — | — |
| debian | apache2 | < apache2 2.4.59-1~deb12u1 (bookworm) | apache2 2.4.59-1~deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_httpd_2.4.58-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_httpd_2.4.61-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_mod_http2_2.0.29-3_on_azure_linux_3.0 | — | — |
| msrc | cbl2_httpd_2.4.58-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_httpd_2.4.59-1_on_cbl_mariner_2.0 | — | — |
| netapp | ontap | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Attack vector: unauthenticated remote attacker sends endless HTTP/2 CONTINUATION frames within a single stream to exhaust server memory (DoS) ↗
- →Root cause: HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2; if the client never stops sending headers, memory is exhausted — monitor for abnormally large or non-terminating HTTP/2 header streams ↗
- →Affected Apache httpd versions: 2.4.17 through 2.4.58; fixed in 2.4.59 — flag servers running these versions receiving high-volume HTTP/2 CONTINUATION frame traffic ↗
- →The attack specifically abuses the HTTP/2 module (mod_http2) via endless continuation frames — detection should focus on HTTP/2 streams with an unusually high number of CONTINUATION frames and no END_HEADERS flag ↗
- ·No practical mitigation was identified by Red Hat other than patching; updating the affected package is the only recommended remediation ↗
- ·After an attack ends, the server is expected to recover on its own without manual intervention ↗
- ·Apple's advisory maps CVE-2024-27316 to an AirDrop quarantine-flag issue (macOS Sonoma 14.6), which is a completely different vulnerability context from the Apache httpd HTTP/2 DoS — do not conflate the two ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_apache7.5
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-11-14
Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateNovember 14, 2024
Alert CodeICSA-24-319-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Improper Input Validation, Improper Check for Unusual or Exceptional Conditions, Out-of-bounds Write, Uncontro
Apple
CVE-2024-27316: macOS Sonoma 14.6
vendor_apple·2024-07-29·CVSS 7.5
CVE-2024-27316 [HIGH] CVE-2024-27316: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-27316
Component: AirDrop
Impact: A file received from AirDrop may not have the quarantine flag applied
Description: This issue was addressed through improved state management.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Apache HTTP Server) — CVE-2024-27316
vendor_oracle·2024-07-15·CVSS 7.5
CVE-2024-27316 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Core (Apache HTTP Server) — CVE-2024-27316
Oracle Oracle Communications Applications Risk Matrix: Core (Apache HTTP Server) vulnerability
CVE: CVE-2024-27316
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2024-04-29·CVSS 7.3
CVE-2024-27316 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
USN-6729-1 fixed vulnerabilities in Apache HTTP Server. This update
provides the corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
Orange Tsai discovered that the Apache HTTP Server incorrectly handled
validating certain input. A remote attacker could possibly use this
issue to perform HTTP request splitting attacks. (CVE-2023-38709)
Keran Mu and Jianjun Chen discovered that the Apache HTTP Server
incorrectly handled validating certain input. A remote attacker could
possibly use this issue to perform HTTP request splitting attacks.
(CVE-2024-24795)
Bartek Nowotarski discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled endless continuati
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2024-04-17·CVSS 7.3
CVE-2024-27316 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
USN-6729-1 fixed several vulnerabilities in Apache. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
Orange Tsai discovered that the Apache HTTP Server incorrectly handled
validating certain input. A remote attacker could possibly use this
issue to perform HTTP request splitting attacks. (CVE-2023-38709)
Keran Mu and Jianjun Chen discovered that the Apache HTTP Server
incorrectly handled validating certain input. A remote attacker could
possibly use this issue to perform HTTP request splitting attacks.
(CVE-2024-24795)
Bartek Nowotarski discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled en
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2024-04-11·CVSS 7.3
CVE-2024-27316 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
Orange Tsai discovered that the Apache HTTP Server incorrectly handled
validating certain input. A remote attacker could possibly use this
issue to perform HTTP request splitting attacks. (CVE-2023-38709)
Keran Mu and Jianjun Chen discovered that the Apache HTTP Server
incorrectly handled validating certain input. A remote attacker could
possibly use this issue to perform HTTP request splitting attacks.
(CVE-2024-24795)
Bartek Nowotarski discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled endless continuation frames. A remote attacker could
possibly use this issue to cause the server to consume resources, leading
to a denial of service. (CVE-2024-27316)
Ins
Microsoft
Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames
vendor_msrc·2024-04-09·CVSS 7.5
CVE-2024-27316 [HIGH] CWE-770 Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames
Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Mariner Relea
Red Hat
httpd: CONTINUATION frames DoS
vendor_redhat·2024-04-03·CVSS 7.5
CVE-2024-27316 [HIGH] CWE-400 httpd: CONTINUATION frames DoS
httpd: CONTINUATION frames DoS
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
A vulnerability was found in how Apache httpd implements the HTTP/2 protocol. There are insufficient limitations placed on the amount of CONTINUATION frames that can be sent within a single stream. This issue could allow an unauthenticated remote attacker to send packets to vulnerable servers, which could use up memory resources to cause a Denial of Service.
Statement: Red Hat rates the security impact of this vulnerability as Moderate, in alignment with upstream Apache. The worst case scenario is memory exhaustion causing a denial of service. Once
Debian
CVE-2024-27316: apache2 - HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 ...
vendor_debian·2024·CVSS 7.5
CVE-2024-27316 [HIGH] CVE-2024-27316: apache2 - HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 ...
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
Scope: local
bookworm: resolved (fixed in 2.4.59-1~deb12u1)
bullseye: resolved (fixed in 2.4.59-1~deb11u1)
forky: resolved (fixed in 2.4.59-1)
sid: resolved (fixed in 2.4.59-1)
trixie: resolved (fixed in 2.4.59-1)
Apache
Apache httpd: CVE-2024-27316
vendor_apache·CVSS 7.5
CVE-2024-27316 Apache httpd: CVE-2024-27316
Apache httpd: CVE-2024-27316
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion. Acknowledgements: finder: Bartek Nowotarski (https://nowotarski.info/) Reported to security team 2024-02-22 Update 2.4.59 released 2024-04-04 Affects 2.4.17 through 2.4.58
Severity: moderate
Affected versions: 2.4.58
OSV
apache2 vulnerabilities
osv·2024-04-29·CVSS 7.3
CVE-2023-38709 [HIGH] apache2 vulnerabilities
apache2 vulnerabilities
USN-6729-1 fixed vulnerabilities in Apache HTTP Server. This update
provides the corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
Orange Tsai discovered that the Apache HTTP Server incorrectly handled
validating certain input. A remote attacker could possibly use this
issue to perform HTTP request splitting attacks. (CVE-2023-38709)
Keran Mu and Jianjun Chen discovered that the Apache HTTP Server
incorrectly handled validating certain input. A remote attacker could
possibly use this issue to perform HTTP request splitting attacks.
(CVE-2024-24795)
Bartek Nowotarski discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled endless continuation frames. A remote attacker could
possibly use this issue to cause the server to cons
OSV
apache2 vulnerabilities
osv·2024-04-17·CVSS 7.3
CVE-2023-38709 [HIGH] apache2 vulnerabilities
apache2 vulnerabilities
USN-6729-1 fixed several vulnerabilities in Apache. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
Orange Tsai discovered that the Apache HTTP Server incorrectly handled
validating certain input. A remote attacker could possibly use this
issue to perform HTTP request splitting attacks. (CVE-2023-38709)
Keran Mu and Jianjun Chen discovered that the Apache HTTP Server
incorrectly handled validating certain input. A remote attacker could
possibly use this issue to perform HTTP request splitting attacks.
(CVE-2024-24795)
Bartek Nowotarski discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled endless continuation frames. A remote attacker could
possibly use this issue to cause th
OSV
apache2 vulnerabilities
osv·2024-04-11·CVSS 7.3
CVE-2023-38709 [HIGH] apache2 vulnerabilities
apache2 vulnerabilities
Orange Tsai discovered that the Apache HTTP Server incorrectly handled
validating certain input. A remote attacker could possibly use this
issue to perform HTTP request splitting attacks. (CVE-2023-38709)
Keran Mu and Jianjun Chen discovered that the Apache HTTP Server
incorrectly handled validating certain input. A remote attacker could
possibly use this issue to perform HTTP request splitting attacks.
(CVE-2024-24795)
Bartek Nowotarski discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled endless continuation frames. A remote attacker could
possibly use this issue to cause the server to consume resources, leading
to a denial of service. (CVE-2024-27316)
OSV
CVE-2024-27316: HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response
osv·2024-04-04·CVSS 7.5
CVE-2024-27316 [HIGH] CVE-2024-27316: HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
GHSA
GHSA-5qc4-82jh-h385: HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response
ghsa_unreviewed·2024-04-04
CVE-2024-27316 [HIGH] CWE-400 GHSA-5qc4-82jh-h385: HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
No detection rules found.
No public exploits indexed.
HackerOne
Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames
hackerone·2024-04-24·CVSS 7.5
CVE-2024-27316 [HIGH] Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames
Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames
I'd like to report Apache httpd vulnerability (CVE-2024-27316) that was recently fixed.
* Advisory: https://httpd.apache.org/security/vulnerabilities_24.html
## Impact
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames (CVE-2024-27316)
Severity: Moderate
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
A
Bugzilla
CVE-2024-27316 httpd: CONTINUATION frames DoS
bugzilla·2024-03-06·CVSS 7.5
CVE-2024-27316 [HIGH] CVE-2024-27316 httpd: CONTINUATION frames DoS
CVE-2024-27316 httpd: CONTINUATION frames DoS
This description was provided in the disclosure from VINCE:
HTTP/2 CONTINUATION frames without the END_HEADERS flag set can be sent in a continuous stream by an attacker to an Apache Httpd implementation, which will not properly terminate the request early, causing an OOM crash.
[note: edited "which will not properly append header information in memory" to "which will not properly terminate the request early" per note from Apache in VINCE]
Discussion:
CVE-2023-44487 is something different i think you are mixing CVE...
---
Created mod_http2 tracking bugs for this issue:
Affects: fedora-all [bug 2273037]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:1786 https://access.redhat.com
Bleepingcomputer
New HTTP/2 DoS attack can crash web servers with a single connection
blogs_bleepingcomputer·2024-04-04
New HTTP/2 DoS attack can crash web servers with a single connection
## New HTTP/2 DoS attack can crash web servers with a single connection
## Bill Toulas
Newly discovered HTTP/2 protocol vulnerabilities called "CONTINUATION Flood" can lead to denial of service (DoS) attacks, crashing web servers with a single TCP connection in some implementations.
HTTP/2 is an update to the HTTP protocol standardized in 2015, designed to improve web performance by introducing binary framing for efficient data transmission, multiplexing to allow multiple requests and responses over a single connection, and header compression to reduce overhead
The new CONTINUATION Flood vulnerabilities were discovered by researcher Barket Nowotarski , who says that it relates to the use of HTTP/2 CONTINUATION frames, which are not properly limited or checked in many implementations of
http://seclists.org/fulldisclosure/2024/Jul/18http://www.openwall.com/lists/oss-security/2024/04/04/4https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://support.apple.com/kb/HT214119https://www.openwall.com/lists/oss-security/2024/04/03/16http://seclists.org/fulldisclosure/2024/Jul/18http://www.openwall.com/lists/oss-security/2024/04/04/4https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.debian.org/debian-lts-announce/2024/05/msg00013.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/FO73U3SLBYFGIW2YKXOK7RI4D6DJSZ2B/https://lists.fedoraproject.org/archives/list/[email protected]/message/MIUBKSCJGPJ6M2U63V6BKFDF725ODLG7/https://security.netapp.com/advisory/ntap-20240415-0013/https://support.apple.com/kb/HT214119https://www.kb.cert.org/vuls/id/421644https://www.openwall.com/lists/oss-security/2024/04/03/16
2024-04-04
Published