Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.
Start learningUpgrade h3 to version 1.15.9, 2.0.1-rc.18 or higher.
h3 is a Minimal H(TTP) framework built for high performance and portability.
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling through the getChunkedCookieCount function. An attacker can cause the server to enter an inefficient cleanup loop by sending a crafted cookie header with a large chunk count value, resulting in excessive resource consumption and server unresponsiveness.
Note: Chunked cookie support was included in 1.15.8 via 61b395e excluded in 1.15.9