Allocation of Resources Without Limits or Throttling in PUPnP - #VU151945
Published: September 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits in the streaming HTTP GET client when processing HTTP response status lines and headers. A remote attacker can send an unbounded stream of header lines without a terminating blank line to cause a denial of service.
The issue affects UpnpOpenHttpGet(), UpnpOpenHttpGetProxy(), UpnpOpenHttpGetEx(), and UpnpGetHttpResponse().