CVE-2025-71031

Water-Melon Melon commit 9df9292 and below is vulnerable to Denial of Service. The HTTP component doesn't have any maximum length. As a result, an excessive request header could cause a denial of service by consuming RAM memory.
Configurations

Configuration 1 (hide)

cpe:2.3:a:melang:melon:*:*:*:*:*:*:*:*

History

25 Feb 2026, 18:47

Type Values Removed Values Added
Summary
  • (es) Water-Melon Melon commit 9df9292 y versiones anteriores es vulnerable a Denegación de Servicio. El componente HTTP no tiene una longitud máxima. Como resultado, una cabecera de solicitud excesiva podría causar una denegación de servicio al consumir memoria RAM.
References () https://suphawith-phusanbai.gitbook.io/book-of-suphawith/my-exploits/cve-2025-71031-denial-of-service-in-melon-c-library - () https://suphawith-phusanbai.gitbook.io/book-of-suphawith/my-exploits/cve-2025-71031-denial-of-service-in-melon-c-library - Exploit, Third Party Advisory
References () https://suphawith-phusanbai.gitbook.io/book-of-suphawith/my-exploits/denial-of-service-in-melon-c-library - () https://suphawith-phusanbai.gitbook.io/book-of-suphawith/my-exploits/denial-of-service-in-melon-c-library - Exploit, Third Party Advisory
CPE cpe:2.3:a:melang:melon:*:*:*:*:*:*:*:*
First Time Melang
Melang melon

05 Feb 2026, 15:16

Type Values Removed Values Added
CWE CWE-400
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

04 Feb 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-04 20:16

Updated : 2026-02-25 18:47


NVD link : CVE-2025-71031

Mitre link : CVE-2025-71031

CVE.ORG link : CVE-2025-71031


JSON object : View

Products Affected

melang

  • melon
CWE
CWE-400

Uncontrolled Resource Consumption