PT-2025-35706 · Mikecao · Mikecao/Flight
Published
2025-09-03
·
Updated
2025-09-03
·
CVE-2014-125127
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
mikecao/flight versions prior to v1.2
Description
The mikecao/flight PHP framework is susceptible to Denial of Service (DoS) attacks. This is due to the eager loading of request bodies within the
Request class constructor. The framework automatically reads the entire request body for every HTTP request, irrespective of application requirements. An attacker can exploit this by sending requests with large payloads, potentially leading to excessive memory consumption, application crashes, or service unavailability. The issue was addressed in version v1.2 by implementing lazy loading of request bodies.Recommendations
Upgrade to version 1.2 or later to resolve this issue.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mikecao/Flight