GHSA-fj9c-wr2v-556hHighCVSS 7.5

The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP...

Published
September 13, 2026
Last Modified
September 13, 2026

🔗 CVE IDs covered (1)

📋 Description

The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request with an unlimited number of headers, if a websocket or JSON-RPC listener is enabled (disabled by default).

🔗 References (4)