Skip to content

Possible crash on malformed HTTP requests

Moderate
babelouest published GHSA-9rp9-65jw-w7vw Feb 13, 2022

Package

ulfius (C)

Affected versions

< 2.7.4

Patched versions

2.7.4

Description

Ulfius Web Framework suffers from a remote memory corruption vulnerability. When parsing malformed HTTP requests, a heap-related initialization bug is triggered resulting in a crash in the server.

Severity

Moderate

CVE ID

CVE-2021-40540

Weaknesses

No CWEs