CVE-2025-49176

A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximum allowed size, potentially causing an integer overflow and bypassing the size check.
Configurations

No configuration.

History

18 Jun 2025, 18:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/06/18/2 -
Summary
  • (es) Se detectó una falla en la extensión Big Requests. La longitud de la solicitud se multiplica por 4 antes de compararla con el tamaño máximo permitido, lo que podría causar un desbordamiento de enteros y omitir la comprobación de tamaño.

17 Jun 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-17 15:15

Updated : 2025-06-18 18:15


NVD link : CVE-2025-49176

Mitre link : CVE-2025-49176

CVE.ORG link : CVE-2025-49176


JSON object : View

Products Affected

No product.

CWE
CWE-190

Integer Overflow or Wraparound