{"id":"GHSA-w8gf-g2vq-j2f4","aliases":[],"url":"https://o3.security/vulnerability/GHSA-w8gf-g2vq-j2f4","summary":"amphp/http-client  Denial of Service via HTTP/2 CONTINUATION Frames","details":"Early versions of `amphp/http-client` with HTTP/2 support (v4.0.0-rc10 to 4.0.0) will collect HTTP/2 `CONTINUATION` frames in an unbounded buffer and will not check the header size limit until it has received the `END_HEADERS` flag, resulting in an OOM crash. Later versions of `amphp/http-client` (v4.1.0-rc1 and up) depend on `amphp/http` for HTTP/2 processing and will therefore need an updated version of `amphp/http`, see [GHSA-qjfw-cvjf-f4fm](https://github.com/amphp/http/security/advisories/GHSA-qjfw-cvjf-f4fm).\n\n## Acknowledgements\n\nThank you to [Bartek Nowotarski](https://nowotarski.info/) for reporting the vulnerability.","published":"2024-04-03T18:49:42Z","modified":"2026-07-08T06:52:51.943094832Z","cvss":{"score":8.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"amphp/http-client","fixedVersion":"4.1.0-rc1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/amphp/http-client/security/advisories/GHSA-w8gf-g2vq-j2f4"},{"type":"WEB","url":"https://github.com/amphp/http/security/advisories/GHSA-qjfw-cvjf-f4fm"},{"type":"PACKAGE","url":"https://github.com/amphp/http-client"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T06:52:51.943094832Z"}}