CVE-2017-9790: Apache Mesos
High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.
When handling a libprocess message wrapped in an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.0-dev crashes if the request path is empty, because the parser assumes the request path always starts with '/'. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable.
Affected products
- Apache Mesos: up to and including 1.1.2; version 1.2.0 only; version 1.2.1 only; version 1.3.0 only; version 1.3.1 only; version 1.4.0-dev only
Published 2017-09-29. Last modified 2026-06-17.