CVE-2023-44386
Summary
| CVE | CVE-2023-44386 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-05 18:15:00 UTC |
| Updated | 2023-10-11 17:47:00 UTC |
| Description | Vapor is an HTTP web framework for Swift. There is a denial of service vulnerability impacting all users of affected versions of Vapor. The HTTP1 error handler closed connections when HTTP parse errors occur instead of passing them on. The issue is fixed as of Vapor release 4.84.2. |
Risk And Classification
Problem Types: CWE-231
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release 4.84.2 - [SECURITY] Incorrect request error handling triggers server crash · vapor/vapor · GitHub | MISC | github.com | |
| Merge pull request from GHSA-3mwq-h3g6-ffhm · vapor/vapor@090464a · GitHub | MISC | github.com | |
| Incorrect request error handling triggers server crash · Advisory · vapor/vapor · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.