CVE-2024-45797

LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Prior to version 0.5.49, unbounded processing of HTTP request and response headers can lead to excessive CPU time and memory utilization, possibly leading to extreme slowdowns. This issue is addressed in 0.5.49.
References
Link Resource
https://github.com/OISF/libhtp/security/advisories/GHSA-rqqp-24ch-248f Vendor Advisory Exploit Issue Tracking Patch
https://redmine.openinfosecfoundation.org/issues/7191 Issue Tracking Exploit Patch Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:oisf:libhtp:*:*:*:*:*:*:*:*

History

09 Jul 2025, 17:02

Type Values Removed Values Added
References () https://github.com/OISF/libhtp/security/advisories/GHSA-rqqp-24ch-248f - () https://github.com/OISF/libhtp/security/advisories/GHSA-rqqp-24ch-248f - Vendor Advisory, Exploit, Issue Tracking, Patch
References () https://redmine.openinfosecfoundation.org/issues/7191 - () https://redmine.openinfosecfoundation.org/issues/7191 - Issue Tracking, Exploit, Patch, Vendor Advisory
CPE cpe:2.3:a:oisf:libhtp:*:*:*:*:*:*:*:*
First Time Oisf
Oisf libhtp

Information

Published : 2024-10-16 19:15

Updated : 2025-07-09 17:02


NVD link : CVE-2024-45797

Mitre link : CVE-2024-45797

CVE.ORG link : CVE-2024-45797


JSON object : View

Products Affected

oisf

  • libhtp
CWE
CWE-770

Allocation of Resources Without Limits or Throttling