WEB Apache HTTP Server nghttp2 Resource Consumption (CVE-2024-27316) state 1-F/Flow

Rule ID

1236035

Severity

High

Description

HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.

Impact

Denial of service

Recommendation

Update vendor's patch.

IPS Category

DoS attacks

IPS Anomaly Group

N/A

IPS Rule Default Action

Deny

References

CVE-2024-27316

ICSA-24-319-04

T1499

Keywords

N/A

Date Created

2024/12/06

Last Updated

2026/08/03