PT-2024-22266 · Unknown · Apollo Router

Ivangoncharov

·

Published

2024-03-06

·

Updated

2026-01-02

·

CVE-2024-28101

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apollo Router versions 0.9.5 through 1.40.2
Description The Apollo Router is subject to a Denial-of-Service (DoS) type issue. When receiving compressed HTTP payloads, affected versions of the Router evaluate the limits.http max request bytes configuration option after the entirety of the compressed payload is decompressed. If affected versions of the Router receive highly compressed payloads, this could result in significant memory consumption while the compressed payload is expanded.
Recommendations For versions 0.9.5 through 1.40.1, upgrade to version 1.40.2 to resolve the issue. For those unable to upgrade, consider implementing mitigations at proxies or load balancers positioned in front of the Router fleet by creating limits on HTTP body upload size.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2024-28101
GHSA-CGQF-3CQ5-WVCJ

Affected Products

Apollo Router