CVE-2024-2653: Amphp Amphp/http
High severity, CVSS 8.2. EPSS: 83.4% chance of exploitation in the next 30 days.
amphp/http will collect CONTINUATION frames in an unbounded buffer and will not check a limit until it has received the set END_HEADERS flag, resulting in an OOM crash.
Affected products
- Amphp Amphp/http: from 2.0.0-beta.1, up to and including 2.1.0; from v1.6.0-rc1, up to and including 1.7.2
- Amphp Amphp/http-Client: from v4.0.0-rc10, up to and including 4.0.0
- Amphp HTTP: from 2.0.0-beta1, up to and including 2.1.0; from v1.6.0-rc1, up to and including 1.7.2
- Amphp HTTP-Client: from v4.0.0-rc10, up to and including 4.0.0
Published 2024-04-03. Last modified 2026-06-17.