Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.Sign up
fix crash when receiving request with invalid framing (CVE-2017-10868) #1459
The worker process of H2O may crash (and automatically respawned depending on the configuration) when it receives a HTTP request with an invalid framing specifier (i.e. content-length or transfer-encoding header).
The crash disrupts other requests in-flight, and therefore is being classified as a DoS vulnerability.
Affected systems: H2O up to version 2.2.2, serving HTTP/1 traffic.