Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as "a=;", an attacker can make an HTTP server allocate a large amount of structs, causing large memory consumption.
References
Configurations
No configuration.
History
04 Nov 2025, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
30 Oct 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
29 Oct 2025, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-29 23:16
Updated : 2025-11-04 22:16
NVD link : CVE-2025-58186
Mitre link : CVE-2025-58186
CVE.ORG link : CVE-2025-58186
JSON object : View
Products Affected
No product.
CWE
No CWE.
