CVE-2024-23837: Fedoraproject Fedora

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP headers, leading to denial of service. This issue is addressed in 0.5.46.

Affected products

  • Fedoraproject Fedora: version 38 only; version 39 only
  • Oisf Libhtp: before 0.5.46 (fixed in 0.5.46)

Published 2024-02-26. Last modified 2026-06-17.