{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aguno1928alos_http/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:guno1928:alos_http:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-55484"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["alos-http (\u003c 0.0.0-20260617230736-314b6783e196)"],"_cs_severities":["low"],"_cs_tags":["dos","vulnerability","webserver"],"_cs_type":"advisory","_cs_vendors":["guno1928"],"content_html":"\u003cp\u003eThe alos-http web framework is susceptible to a remote denial-of-service vulnerability (CVE-2026-55484) due to improper input validation in the 'sanitizeRequestPath' function. When the framework receives an HTTP request with a path starting with the '?' character (e.g., 'GET ? HTTP/1.1'), the internal request parser passes the path to 'sanitizeRequestPath'. This function attempts to index the first byte of the path after query string stripping without verifying that the resulting string is non-empty. This results in an out-of-bounds panic. Because this parsing occurs in the connection-worker goroutine before any user-defined middleware or recovery handlers are executed, the panic is unrecoverable, leading to an immediate process crash. This affects HTTP/1.1, HTTP/2, and HTTP/3 protocols, potentially rendering services unavailable until restarted.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP request with a malformed path starting with a '?' character.\u003c/li\u003e\n\u003cli\u003eAttacker transmits the request via TCP (HTTP/1.1 or HTTP/2) or UDP (HTTP/3) to the target alos-http server.\u003c/li\u003e\n\u003cli\u003eThe server's connection-worker goroutine receives the request head.\u003c/li\u003e\n\u003cli\u003eThe request parser invokes 'sanitizeRequestPath' with the malicious path.\u003c/li\u003e\n\u003cli\u003eThe 'sanitizeRequestPath' function strips the query string, resulting in an empty string.\u003c/li\u003e\n\u003cli\u003eThe function attempts to access the first index of the empty string.\u003c/li\u003e\n\u003cli\u003eA runtime panic triggers due to an out-of-bounds index access.\u003c/li\u003e\n\u003cli\u003eThe entire server process crashes, resulting in total service denial.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in an immediate and total denial of service for the target application. Because the crash occurs during the request parsing phase before any request logging or middleware execution, the impact is consistent across all deployments using the vulnerable framework versions. The vulnerability has been confirmed in alos-http versions prior to 0.0.0-20260617230736-314b6783e196.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the alos-http framework to version 0.0.0-20260617230736-314b6783e196 or later immediately to patch CVE-2026-55484.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to web application firewalls or reverse proxies to block requests where the URI path begins with a '?' character.\u003c/li\u003e\n\u003cli\u003eMonitor webserver access logs for anomalous 400-series status codes or service-level process restarts that lack associated handler logs, which may indicate crash attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T21:14:12Z","date_published":"2026-08-28T21:14:12Z","id":"https://feed.craftedsignal.io/briefs/2026-08-alos-http-dos/","summary":"An unauthenticated remote denial-of-service vulnerability in alos-http allows attackers to crash the server process by sending a single malformed HTTP request starting with a '?' character.","title":"Unauthenticated Remote Denial of Service in alos-http","url":"https://feed.craftedsignal.io/briefs/2026-08-alos-http-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:guno1928:alos_http:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}