资源分配缺乏限制或节流(Allocation of Resources Without Limits or Throttling) 漏洞存在于 Elixir 的 mint 库中。该漏洞允许远程 HTTP 服务器耗尽客户端主机上的内存,从而导致拒绝服务(DoS)。 具体而言,两个 HTTP/1 响应解析器状态会无限制地累积服务器数据。在 中, 在状态行不完整时,将未消费的数据存储在 中; 对于未终止的块扩展行执行相同操作。这两种状态都在等待一个服务器无需发送的 CRLF(回车换行),而 会被前置到后续每条套接字消息之
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| elixir-mint | mint | 0.1.0< 1.10.0 |
affected |
c088e4b6430545338841ab8d294369e45d39856a< 19be5558b6a317e271c78666498dd78b151e490a |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| elixir-mint | mint | 0.1.0 ~ 1.10.0 |
cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*
|
|
| elixir-mint | mint | c088e4b6430545338841ab8d294369e45d39856a ~ 19be5558b6a317e271c78666498dd78b151e490a |
cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet