CVE-2024-2757

In PHP 8.3.* before 8.3.5, function mb_encode_mimeheader() runs endlessly for some inputs that contain long strings of non-space characters followed by a space. This could lead to a potential DoS attack if a hostile user sends data to an application that uses this function.
Configurations

Configuration 1 (hide)

cpe:2.3:a:php:php:*:*:*:*:*:*:*:*

History

04 Nov 2025, 18:16

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/[email protected]/message/KJZK3X6B7FBE32FETDSMRLJXTFTHKWSY/ -

Information

Published : 2024-04-29 04:15

Updated : 2025-11-04 18:16


NVD link : CVE-2024-2757

Mitre link : CVE-2024-2757

CVE.ORG link : CVE-2024-2757


JSON object : View

Products Affected

php

  • php
CWE
NVD-CWE-noinfo CWE-400

Uncontrolled Resource Consumption