CVE-2026-103471
Received Received - Intake

Restbed HTTP Header Buffer Overflow Vulnerability

Vulnerability report for CVE-2026-103471, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulnCheck

Description

restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated attackers to exhaust server memory. Attackers can open TCP connections and stream bytes indefinitely without sending the header delimiter, forcing the server to allocate unbounded heap memory until the process is killed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
restbed restbed to 5.0.0 (inc)
corvusoft restbed to 5.0.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-103471 is a high-severity Denial of Service (DoS) vulnerability in restbed versions up to 5.0.0. It allows remote unauthenticated attackers to exhaust server memory by sending HTTP requests with unbounded headers. The server fails to enforce a maximum size limit on headers, causing it to allocate memory indefinitely until the process crashes.

Detection Guidance

Monitor for unusually high memory usage on restbed servers, particularly when handling HTTP requests. Check for processes consuming excessive heap memory without clear cause. Use tools like 'top', 'htop', or 'ps' to track memory usage of restbed processes. Inspect network traffic for connections that send continuous data without completing HTTP headers or WebSocket frames.

Impact Analysis

This vulnerability can cause your restbed-based server to crash or become unresponsive due to memory exhaustion. It requires no authentication or user interaction, making it easy for attackers to disrupt service availability. Systems handling high traffic or critical services are particularly at risk.

Mitigation Strategies

Upgrade restbed to a patched version that enforces maximum header and WebSocket frame size limits. If upgrading is not possible, implement network-level protections like rate limiting or WAF rules to block malformed requests. Temporarily disable WebSocket support if not required. Monitor server memory usage closely until mitigation is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103471. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart