<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Corvusoft - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/corvusoft/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 18:36:14 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/corvusoft/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Memory Exhaustion Vulnerability in restbed Framework (CVE-2026-103471)</title><link>https://feed.craftedsignal.io/briefs/2026-09-restbed-memory-exhaustion/</link><pubDate>Wed, 30 Sep 2026 18:36:14 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-restbed-memory-exhaustion/</guid><description>The restbed framework through version 5.0.0 is vulnerable to memory exhaustion due to the lack of a maximum size limit on incoming HTTP request headers.</description><content:encoded><![CDATA[<p>The Corvusoft restbed framework through version 5.0.0 contains a vulnerability in its HTTP header processing logic that fails to enforce a maximum size limit on incoming buffers. This design flaw allows remote, unauthenticated attackers to perform a Denial of Service (DoS) attack by opening a TCP connection to the server and streaming data indefinitely without sending the HTTP header delimiter (typically <code>\r\n\r\n</code>).</p>
<p>Because the application continues to allocate heap memory for these incoming bytes in anticipation of a completed header, an attacker can rapidly exhaust the host system's available memory. This behavior forces the process to crash or triggers out-of-memory (OOM) killer events on the host, rendering the service unavailable. This vulnerability is particularly critical for internet-facing applications utilizing restbed, as it requires minimal effort from an attacker to trigger the crash.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-103471 results in an immediate denial of service, rendering the affected restbed-based application unresponsive. Because the attack requires no authentication and minimal network traffic to maintain the connection, attackers can easily target critical infrastructure, potentially crashing multiple instances of the service simultaneously. Organizations should prioritize updating their software or implementing rate limiting and header size restrictions at the reverse proxy layer to mitigate the impact of this vulnerability.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor application memory usage for sustained, abnormal increases that correlate with high volumes of long-lived, idle TCP connections.</li>
<li>Implement request header size limits at the perimeter (e.g., Nginx, HAProxy, or cloud WAF) to drop requests that exceed standard length expectations before they reach the restbed application.</li>
<li>If possible, upgrade to a version of restbed that includes proper buffer size validation (verify vendor patch status).</li>
<li>Use network traffic monitoring to identify and drop idle TCP connections that remain open for extended durations without completing an HTTP request cycle.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>denial-of-service</category><category>vulnerability</category><category>restbed</category><category>websocket</category><category>memory-exhaustion</category></item></channel></rss>