---
id: CVE-2026-103471
title: >-
  restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum
  size limit, allowing remote unauthenticated attackers to exhaust server memory
summary: >-
  restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum
  size limit, allowing remote unauthenticated attackers to exhaust server
  memory. Attackers can open TCP connections and stream bytes indefinitely
  without sendi…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
vendor: Corvusoft
product: restbed
affected:
  - restbed <= 5.0.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T20:17:31.283'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103471'
references:
  - url: 'https://github.com/Corvusoft/restbed'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Corvusoft/restbed/blob/e1227a297ce6d4e9f78222456507b29bb8ab77e9/src/corvusoft/restbed/detail/service_impl.cpp#L554
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Corvusoft/restbed/blob/e1227a297ce6d4e9f78222456507b29bb8ab77e9/src/corvusoft/restbed/session.cpp#L200
    label: disclosure@vulncheck.com
  - url: 'https://github.com/Corvusoft/restbed/issues/558'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/restbed-through-5.0.0-denial-of-service-via-unbounded-header-buffering
    label: disclosure@vulncheck.com
  - url: 'https://github.com/Corvusoft/restbed/issues/558'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-30T19:17:48.617816Z'
ingestedAt: '2026-09-30T18:17:24.548Z'
---

## Overview

restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated attackers to exhaust server memory. Attackers can open TCP connections and stream bytes indefinitely without sending the header delimiter, forcing the server to allocate unbounded heap memory until the process is killed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
