OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-103471

HIGH · CVSS 7.5 EPSS 0.55% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability allows remote unauthenticated attackers to exploit the restbed framework by sending excessively large HTTP request headers, leading to unbounded memory allocation on the server. This can result in server memory exhaustion, potentially causing service disruptions or crashes. Organizations using affected versions of restbed should prioritize patching this vulnerability to mitigate the risk of denial-of-service attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-103471
Severity
HIGH
CVSS
7.5
EPSS
0.55%

Original NVD Description

restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated attackers to exhaust server memory. Attackers can open TCP connections and stream bytes indefinitely without sending the header delimiter, forcing the server to allocate unbounded heap memory until the process is killed.