{"id":"GHSA-w8gf-g2vq-j2f4","summary":"amphp/http-client  Denial of Service via HTTP/2 CONTINUATION Frames","details":"Early versions of `amphp/http-client` with HTTP/2 support (v4.0.0-rc10 to 4.0.0) will collect HTTP/2 `CONTINUATION` frames in an unbounded buffer and will not check the header size limit until it has received the `END_HEADERS` flag, resulting in an OOM crash. Later versions of `amphp/http-client` (v4.1.0-rc1 and up) depend on `amphp/http` for HTTP/2 processing and will therefore need an updated version of `amphp/http`, see [GHSA-qjfw-cvjf-f4fm](https://github.com/amphp/http/security/advisories/GHSA-qjfw-cvjf-f4fm).\n\n## Acknowledgements\n\nThank you to [Bartek Nowotarski](https://nowotarski.info/) for reporting the vulnerability.","modified":"2026-07-08T06:52:51.943094832Z","published":"2024-04-03T18:49:42Z","related":["CVE-2024-2653"],"database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-04-03T18:49:42Z","nvd_published_at":null,"cwe_ids":["CWE-770","CWE-789"]},"references":[{"type":"WEB","url":"https://github.com/amphp/http-client/security/advisories/GHSA-w8gf-g2vq-j2f4"},{"type":"WEB","url":"https://github.com/amphp/http/security/advisories/GHSA-qjfw-cvjf-f4fm"},{"type":"PACKAGE","url":"https://github.com/amphp/http-client"}],"affected":[{"package":{"name":"amphp/http-client","ecosystem":"Packagist","purl":"pkg:composer/amphp/http-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0-rc10"},{"fixed":"4.1.0-rc1"}]}],"versions":["v4.0.0","v4.0.0-rc10","v4.0.0-rc11"],"database_specific":{"last_known_affected_version_range":"\u003c= 4.0.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/04/GHSA-w8gf-g2vq-j2f4/GHSA-w8gf-g2vq-j2f4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"}]}