CVE Vulnerabilities

CVE-2023-44386

Improper Handling of Extra Values

Published: Oct 05, 2023 | Modified: Oct 11, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Vapor is an HTTP web framework for Swift. There is a denial of service vulnerability impacting all users of affected versions of Vapor. The HTTP1 error handler closed connections when HTTP parse errors occur instead of passing them on. The issue is fixed as of Vapor release 4.84.2.

Weakness

The product does not handle or incorrectly handles when more values are provided than expected.

Affected Software

Name Vendor Start Version End Version
Vapor Vapor 4.83.2 (including) 4.84.2 (excluding)

References