WEB Apache HTTP Server nghttp2 Resource Consumption (CVE-2024-27316) state 1-F/Flow
Rule ID
1236035
Severity
High
Description
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
Impact
Denial of service
Recommendation
Update vendor's patch.
IPS Category
DoS attacks
IPS Anomaly Group
N/A
IPS Rule Default Action
Deny
References
Keywords
N/A
Date Created
2024/12/06
Last Updated