← Back to browse · API

CVE-2024-27316

Severity
HIGH
CVSS
7.5
EPSS
0.91327
Risk score
61.96
CISA KEV
No
PoC
No
Published
2024-04-04
Modified
2025-11-04
First seen
2026-08-07
Aliases
EUVD-2024-24531, GHSA-5QC4-82JH-H385
Products
Apache Software Foundation:Apache HTTP Server 2.4.17 ≤2.4.58
Sources
euvd EUVD-2024-24531

Description

HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.

References