← Back to browse · API

CVE-2019-5645

Severity
HIGH
CVSS
7.5
EPSS
0.41688
Risk score
44.59
CISA KEV
No
PoC
No
Published
2020-09-01
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2019-15220, GHSA-WP3V-G466-8G44
Products
Rapid7:Metasploit Framework 5.0.27 ≤5.0.27
Sources
euvd EUVD-2019-15220

Description

By sending a specially crafted HTTP GET request to a listening Rapid7 Metasploit HTTP handler, an attacker can register an arbitrary regular expression. When evaluated, this malicious handler can either prevent new HTTP handler sessions from being established, or cause a resource exhaustion on the Metasploit server.

References