Back

LOW

Mozilla: Denial of Service using HTTP/2 CONTINUATION frames

Published Apr 16, 2024

Description

There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the browser. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.

Affected products

Remediation

Red Hat statement

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Apr 16, 2024
Updated Mar 28, 2025
Reserved Apr 4, 2024
CISA Vulnrichment
Updated May 24, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Apr 16, 2024
ENISA EUVD
Assigner mozilla
Published Apr 16, 2024
Updated Mar 28, 2025
Exploited since n/a
EUVD-2024-31892