mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 10:41:43 +00:00
18 lines
765 B
Markdown
18 lines
765 B
Markdown
![]() |
### [CVE-2023-34188](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34188)
|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers. By sending a single attack payload over TCP, an attacker can cause an infinite loop in which the server continuously reparses that payload, and does not respond to any other requests.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
- https://github.com/cesanta/mongoose/pull/2197
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/narfindustries/http-garden
|
||
|
|