The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers. By sending a single attack payload over TCP, an attacker can cause an infinite loop in which the server continuously reparses that payload, and does not respond to any other requests.
References
Configurations
History
No history.
Information
Published : 2023-06-23 20:15
Updated : 2023-09-06 17:15
NVD link : CVE-2023-34188
Mitre link : CVE-2023-34188
CVE.ORG link : CVE-2023-34188
JSON object : View
Products Affected
cesanta
- mongoose
CWE