CVE-2026-103471 Details
Description
restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated attackers to exhaust server memory. Attackers can open TCP connections and stream bytes indefinitely without sending the header delimiter, forcing the server to allocate unbounded heap memory until the process is killed.
A denial-of-service vulnerability has been identified in Restbed versions through 5.0.0. The issue arises because the framework buffers HTTP request headers without enforcing a maximum size limit. This flaw allows remote unauthenticated attackers to exhaust server memory by opening TCP connections and streaming bytes indefinitely, without sending the header delimiter. As a result, the server allocates unbounded heap memory, leading to process termination.
Users are advised to update to Restbed version 5.0.1 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Corvusoft/restbed/issues/558 | CISA-ADP | ExploitIssue TrackingTechnical AnalysisVendor |
| https://github.com/Corvusoft/restbed | [email protected] | Vendor |
| https://github.com/Corvusoft/restbed/blob/e1227a297ce6d4e9f78222456507b29bb8ab77e9/src/corvusoft/restbed/detail/service_impl.cpp#L554 | [email protected] | |
| https://github.com/Corvusoft/restbed/blob/e1227a297ce6d4e9f78222456507b29bb8ab77e9/src/corvusoft/restbed/session.cpp#L200 | [email protected] | Source CodeVendor |
| https://github.com/Corvusoft/restbed/issues/558 | [email protected] | ExploitIssue TrackingTechnical AnalysisVendor |
| https://www.vulncheck.com/advisories/restbed-through-5.0.0-denial-of-service-via-unbounded-header-buffering | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Corvusoft restbed | <= 5.0.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion