Releases23
Frequency3 months 3 weeks
Last Release
Stars103
HTTP primitives which can be shared by servers and clients.

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
>= 2.0.0, < 2.1.1, < 1.7.38.2 HIGH

amphp/http will collect CONTINUATION frames in an unbounded buffer and will not check a limit until it has received the set END_HEADERS flag, resulting in an OOM crash.