{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "extracted_events": [
              {
                "introduced": "2.0.0-beta.1"
              },
              {
                "last_affected": "2.1.0"
              },
              {
                "introduced": "v1.6.0-rc1"
              },
              {
                "last_affected": "1.7.2"
              }
            ],
            "source": "AFFECTED_FIELD"
          },
          "events": [
            {
              "introduced": "66680c665a2d62970da4a11bbd8fc4fbc0f0d0ed"
            },
            {
              "last_affected": "9f3500bef4bb15cf41987f21136539c0a06555a3"
            },
            {
              "introduced": "d2c00e3c48dc0511d2cea0d6fe73ea084f673aa4"
            },
            {
              "last_affected": "68c61d2f81be3495b692367df2246d9548748db0"
            }
          ],
          "repo": "https://github.com/amphp/http",
          "type": "GIT"
        }
      ]
    },
    {
      "ranges": [
        {
          "database_specific": {
            "extracted_events": [
              {
                "introduced": "v4.0.0-rc10"
              },
              {
                "last_affected": "4.0.0"
              }
            ],
            "source": "AFFECTED_FIELD"
          },
          "events": [
            {
              "introduced": "c371feeb8047d199158c68d9e22ccc20d9071f09"
            },
            {
              "last_affected": "6ae1baaabb6ce104f1b636a5e117ced798087ed4"
            }
          ],
          "repo": "https://github.com/amphp/http-client",
          "type": "GIT"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "certcc",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/2xxx/CVE-2024-2653.json"
  },
  "details": "amphp/http will collect CONTINUATION frames in an unbounded buffer and will not check a limit until it has received the set END_HEADERS flag, resulting in an OOM crash.",
  "id": "CVE-2024-2653",
  "modified": "2026-08-12T03:51:17.130575616Z",
  "published": "2024-04-03T17:18:29.944Z",
  "references": [
    {
      "type": "WEB",
      "url": "http://www.openwall.com/lists/oss-security/2024/04/03/16"
    },
    {
      "type": "WEB",
      "url": "https://www.kb.cert.org/vuls/id/421644"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/2xxx/CVE-2024-2653.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/amphp/http-client/security/advisories/GHSA-w8gf-g2vq-j2f4"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/amphp/http/security/advisories/GHSA-qjfw-cvjf-f4fm"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2653"
    }
  ],
  "related": [
    "GHSA-w8gf-g2vq-j2f4",
    "GHSA-qjfw-cvjf-f4fm"
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "CVE-2024-2653"
}