
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
CVE-2024-27316 is a vulnerability in Apache HTTP Server affecting versions 2.4.17 through 2.4.58. The vulnerability was discovered by Bartek Nowotarski and disclosed on February 22, 2024. The issue involves HTTP/2 incoming headers exceeding the limit being temporarily buffered in nghttp2 to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion (Apache Security, CERT VU).
The vulnerability is related to the handling of HTTP/2 CONTINUATION frames in the Apache HTTP Server. When processing HTTP/2 headers that exceed the limit, the server temporarily buffers them in nghttp2 to generate an HTTP 413 response. However, if a client continues sending headers without setting the END_HEADERS flag, the server keeps accumulating data, leading to memory exhaustion. The vulnerability has been assigned a CVSS v3.1 base score of 7.5 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (NVD).
The primary impact of this vulnerability is the potential for Denial of Service (DoS) attacks. An attacker can exploit this vulnerability by sending continuous streams of HTTP/2 CONTINUATION frames without the END_HEADERS flag set, causing the server to consume excessive memory resources until it crashes (CERT VU).
The vulnerability has been fixed in Apache HTTP Server version 2.4.59. Users running affected versions (2.4.17 through 2.4.58) are strongly recommended to upgrade to version 2.4.59 or later to address this security issue (Apache Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”