CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.5. Its EPSS score suggests a 91.3% probability of exploitation in the next 30 days.
CVE
CVE-2024-27316
Severity
HIGH
CVSS
7.5
EPSS
91.33%
Original NVD Description
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
Related CVEs
Other vulnerabilities affecting the same vendor(s)