CVE-2019-3833: Fedoraproject Fedora
High severity, CVSS 7.5. EPSS: 15.2% chance of exploitation in the next 30 days.
Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_connection() when parsing specially crafted HTTP requests. A remote, unauthenticated attacker can exploit this vulnerability by sending malicious HTTP request to cause denial of service to openwsman server.
Affected products
- Fedoraproject Fedora: version 28 only; version 29 only; version 30 only
- Opensuse Leap: version 15.0 only; version 42.3 only
- Openwsman Project Openwsman: up to and including 2.6.9
Published 2019-03-14. Last modified 2026-06-17.