cbcvebase.
CVE-2024-27316
published 2024-04-04

CVE-2024-27316: HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not…

PriorityP359high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
91.33%
99.8th percentile
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.

Affected

14 ranges
VendorProductVersion rangeFixed in
apachehttp_server>= 2.4.17 < 2.4.592.4.59
apachehttpd
apache_software_foundationapache_http_server2.4.17 – 2.4.58
applemacos_sonoma
debianapache2< apache2 2.4.59-1~deb12u1 (bookworm)apache2 2.4.59-1~deb12u1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
msrcazl3_httpd_2.4.58-4_on_azure_linux_3.0
msrcazl3_httpd_2.4.61-1_on_azure_linux_3.0
msrcazl3_mod_http2_2.0.29-3_on_azure_linux_3.0
msrccbl2_httpd_2.4.58-1_on_cbl_mariner_2.0
msrccbl2_httpd_2.4.59-1_on_cbl_mariner_2.0
netappontap

Detection & IOCsextracted from sources · hover to see the quote

  • Attack vector: unauthenticated remote attacker sends endless HTTP/2 CONTINUATION frames within a single stream to exhaust server memory (DoS)
  • Root cause: HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2; if the client never stops sending headers, memory is exhausted — monitor for abnormally large or non-terminating HTTP/2 header streams
  • Affected Apache httpd versions: 2.4.17 through 2.4.58; fixed in 2.4.59 — flag servers running these versions receiving high-volume HTTP/2 CONTINUATION frame traffic
  • The attack specifically abuses the HTTP/2 module (mod_http2) via endless continuation frames — detection should focus on HTTP/2 streams with an unusually high number of CONTINUATION frames and no END_HEADERS flag
  • ·No practical mitigation was identified by Red Hat other than patching; updating the affected package is the only recommended remediation
  • ·After an attack ends, the server is expected to recover on its own without manual intervention
  • ·Apple's advisory maps CVE-2024-27316 to an AirDrop quarantine-flag issue (macOS Sonoma 14.6), which is a completely different vulnerability context from the Apache httpd HTTP/2 DoS — do not conflate the two

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_apache7.5
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.3HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.