CVE-2024-45797

LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Prior to version 0.5.49, unbounded processing of HTTP request and response headers can lead to excessive CPU time and memory utilization, possibly leading to extreme slowdowns. This issue is addressed in 0.5.49.
CVSS

No CVSS.

References
Link Resource
https://github.com/OISF/libhtp/security/advisories/GHSA-rqqp-24ch-248f Vendor Advisory Exploit Issue Tracking Patch
https://redmine.openinfosecfoundation.org/issues/7191 Issue Tracking Exploit Patch Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:oisf:libhtp:*:*:*:*:*:*:*:*

History

09 Jul 2025, 17:02

Type Values Removed Values Added
First Time Oisf libhtp
Oisf
CPE cpe:2.3:a:oisf:libhtp:*:*:*:*:*:*:*:*
CWE CWE-770
References () https://github.com/OISF/libhtp/security/advisories/GHSA-rqqp-24ch-248f - () https://github.com/OISF/libhtp/security/advisories/GHSA-rqqp-24ch-248f - Vendor Advisory, Exploit, Issue Tracking, Patch
References () https://redmine.openinfosecfoundation.org/issues/7191 - () https://redmine.openinfosecfoundation.org/issues/7191 - Issue Tracking, Exploit, Patch, Vendor Advisory

16 Oct 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-16 19:15

Updated : 2025-07-09 17:02


NVD link : CVE-2024-45797

Mitre link : CVE-2024-45797


JSON object : View

Products Affected

oisf

  • libhtp
CWE

No CWE.