CVE-2024-28871Allocation of Resources Without Limits or Throttling in Libhtp

Severity
7.5HIGHNVD
EPSS
0.1%
top 66.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 4
Latest updateOct 9

Description

LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Version 0.5.46 may parse malformed request traffic, leading to excessive CPU usage. Version 0.5.47 contains a patch for the issue. No known workarounds are available.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

Debianoisf/libhtp< 1:0.5.47-1+1
Ubuntuoisf/libhtp< 0.5.15-1ubuntu0.1~esm1+4
CVEListV5oisf/libhtp= 0.5.46
NVDoisf/libhtp0.5.46

Patches

🔴Vulnerability Details

3
OSV
libhtp vulnerabilities2025-10-09
CVEList
Excessive CPU used on malformed traffic2024-04-04
OSV
CVE-2024-28871: LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces2024-04-04

📋Vendor Advisories

2
Ubuntu
LibHTP vulnerabilities2025-10-09
Debian
CVE-2024-28871: libhtp - LibHTP is a security-aware parser for the HTTP protocol and the related bits and...2024
CVE-2024-28871 — Oisf Libhtp vulnerability | cvebase