CVE-2024-45797

LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Prior to version 0.5.49, unbounded processing of HTTP request and response headers can lead to excessive CPU time and memory utilization, possibly leading to extreme slowdowns. This issue is addressed in 0.5.49.
Configurations

Configuration 1 (hide)

cpe:2.3:a:oisf:libhtp:*:*:*:*:*:*:*:*

History

03 Nov 2025, 19:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/09/msg00009.html -
References () https://github.com/OISF/libhtp/security/advisories/GHSA-rqqp-24ch-248f - Vendor Advisory, Exploit, Issue Tracking, Patch () https://github.com/OISF/libhtp/security/advisories/GHSA-rqqp-24ch-248f - Exploit, Issue Tracking, Patch, Vendor Advisory
References () https://redmine.openinfosecfoundation.org/issues/7191 - Issue Tracking, Exploit, Patch, Vendor Advisory () https://redmine.openinfosecfoundation.org/issues/7191 - Exploit, Issue Tracking, Patch, Vendor Advisory

09 Jul 2025, 17:02

Type Values Removed Values Added
CPE cpe:2.3:a:oisf:libhtp:*:*:*:*:*:*:*:*
First Time Oisf libhtp
Oisf
References () https://github.com/OISF/libhtp/security/advisories/GHSA-rqqp-24ch-248f - () https://github.com/OISF/libhtp/security/advisories/GHSA-rqqp-24ch-248f - Vendor Advisory, Exploit, Issue Tracking, Patch
References () https://redmine.openinfosecfoundation.org/issues/7191 - () https://redmine.openinfosecfoundation.org/issues/7191 - Issue Tracking, Exploit, Patch, Vendor Advisory

18 Oct 2024, 12:53

Type Values Removed Values Added
Summary
  • (es) LibHTP es un analizador que tiene en cuenta la seguridad del protocolo HTTP y sus componentes relacionados. Antes de la versión 0.5.49, el procesamiento ilimitado de los encabezados de solicitud y respuesta HTTP podía generar un uso excesivo de la memoria y del tiempo de CPU, lo que posiblemente provocara ralentizaciones extremas. Este problema se solucionó en la versión 0.5.49.

16 Oct 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-16 19:15

Updated : 2025-11-03 19:15


NVD link : CVE-2024-45797

Mitre link : CVE-2024-45797

CVE.ORG link : CVE-2024-45797


JSON object : View

Products Affected

oisf

  • libhtp
CWE
CWE-770

Allocation of Resources Without Limits or Throttling