HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.CreditsBartek Nowotarski (https://nowotarski.info/)Referenceshttpd.apache.org/security/vulnerabilities_24.htmlhttps://www.openwall.com/lists/oss-security/2024/04/03/16http://www.openwall.com/lists/oss-security/2024/04/04/4https://support.apple.com/kb/HT214119http://seclists.org/fulldisclosure/2024/Jul/18