VendorsOISFlibhtpall versions
Vulnerabilities

OISF Libhtp

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2018-10243
htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authorization digest header.
Published 2019-04-04 · Modified
9.8EPSS 0.023
CVE-2015-0928
libhtp 0.5.15 allows remote attackers to cause a denial of service (NULL pointer dereference).
Published 2017-08-28 · Modified
7.5EPSS 0.023
CVE-2024-23837
LibHTP unbounded folded header handling leads to denial service
Published 2024-02-26 · Modified
7.5EPSS 0.012
CVE-2024-28871
Excessive CPU used on malformed traffic
Published 2024-04-04 · Analyzed
7.5EPSS 0.008
CVE-2024-45797
LibHTP's unbounded header handling leads to denial service
Published 2024-10-16 · Modified
7.5EPSS 0.007
CVE-2025-53537
LibHTP's memory leak with lzma can lead to resource starvation
Published 2025-07-23 · Analyzed
7.5EPSS 0.004
CVE-2019-17420
In OISF LibHTP before 0.5.31, as used in Suricata 4.1.4 and other products, an HTTP protocol parsing error causes the http_header signature to not alert on a response with a single \r\n ending.
Published 2019-10-09 · Modified
5.3EPSS 0.014