CVE-2026-103471: Allocation of Resources Without Limits or Throttling in Corvusoft restbed
CVE-2026-103471 is a high-severity vulnerability in Corvusoft restbed versions up to 5.0.0. The software buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated attackers to exhaust server memory by sending incomplete headers indefinitely. This can cause the server process to be killed due to unbounded heap memory allocation.
AI Analysis
Technical Summary
restbed versions up to and including 5.0.0 do not enforce a maximum size limit on HTTP request headers. Remote unauthenticated attackers can exploit this by opening TCP connections and streaming bytes without sending the header delimiter, causing the server to allocate memory indefinitely. This results in resource exhaustion and potential denial of service.
Potential Impact
The vulnerability allows remote unauthenticated attackers to exhaust server memory by sending HTTP headers without size limits, leading to denial of service through process termination due to unbounded heap memory allocation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider implementing network-level protections such as connection rate limiting or timeouts to mitigate resource exhaustion.
CVE-2026-103471: Allocation of Resources Without Limits or Throttling in Corvusoft restbed
Description
CVE-2026-103471 is a high-severity vulnerability in Corvusoft restbed versions up to 5.0.0. The software buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated attackers to exhaust server memory by sending incomplete headers indefinitely. This can cause the server process to be killed due to unbounded heap memory allocation.
CVSS v4.0
Score 8.7high
Affected software
Corvusoft
restbed
pkg:github/corvusoft/restbedRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
restbed versions up to and including 5.0.0 do not enforce a maximum size limit on HTTP request headers. Remote unauthenticated attackers can exploit this by opening TCP connections and streaming bytes without sending the header delimiter, causing the server to allocate memory indefinitely. This results in resource exhaustion and potential denial of service.
Potential Impact
The vulnerability allows remote unauthenticated attackers to exhaust server memory by sending HTTP headers without size limits, leading to denial of service through process termination due to unbounded heap memory allocation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider implementing network-level protections such as connection rate limiting or timeouts to mitigate resource exhaustion.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-30T16:02:59.183Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abd640f2a4e24523d7a0fd1
Added to database: 09/30/2026, 19:33:35 UTC
Last enriched: 09/30/2026, 19:47:53 UTC
Last updated: 10/01/2026, 04:55:45 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.