The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers. By sending a single attack payload over TCP, an attacker can cause an infinite loop in which the server continuously reparses that payload, and does not respond to any other requests.
CVE ID: CVE-2023-34188
CVSS Base Severity: LOW
CVSS Base Score: 0.0
Vendor: n/a
Product: n/a
EPSS Score: 0.16% (probability of being exploited)
EPSS Percentile: 53.67% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)