CVE-2024-45797Allocation of Resources Without Limits or Throttling in Libhtp

Severity
7.5HIGHNVD
EPSS
0.4%
top 38.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 16
Latest updateOct 9

Description

LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Prior to version 0.5.49, unbounded processing of HTTP request and response headers can lead to excessive CPU time and memory utilization, possibly leading to extreme slowdowns. This issue is addressed in 0.5.49.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

CVEListV5oisf/libhtp< 0.5.49
NVDoisf/libhtp< 0.5.49
Debianoisf/libhtp< 1:0.5.36-1+deb11u1+3
Ubuntuoisf/libhtp< 0.5.15-1ubuntu0.1~esm1+4

Patches

🔴Vulnerability Details

3
OSV
libhtp vulnerabilities2025-10-09
CVEList
LibHTP's unbounded header handling leads to denial service2024-10-16
OSV
CVE-2024-45797: LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces2024-10-16

📋Vendor Advisories

2
Ubuntu
LibHTP vulnerabilities2025-10-09
Debian
CVE-2024-45797: libhtp - LibHTP is a security-aware parser for the HTTP protocol and the related bits and...2024
CVE-2024-45797 — Oisf Libhtp vulnerability | cvebase