QID 997936
Date Published: 2024-04-04
QID 997936: PHP (Composer) Security Update for amphp/http (GHSA-qjfw-cvjf-f4fm)
amphp/http will collect HTTP/2 CONTINUATION frames in an unbounded buffer and will not check the header size limit until it has received the END_HEADERS flag, resulting in an OOM crash. amphp/http-client and amphp/http-server are indirectly affected if they're used with an unpatched version of amphp/http. Early versions of amphp/http-client with HTTP/2 support (v4.0.0-rc10 to 4.0.0) are also directly affected.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-qjfw-cvjf-f4fm for updates and patch information.
Vendor References
- GHSA-qjfw-cvjf-f4fm -
github.com/advisories/GHSA-qjfw-cvjf-f4fm
CVEs related to QID 997936
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qjfw-cvjf-f4fm | amphp/http |
|