In PHP 8.3.* before 8.3.5, function mb_encode_mimeheader() runs endlessly for some inputs that contain long strings of non-space characters followed by a space. This could lead to a potential DoS attack if a hostile user sends data to an application that uses this function.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00603}

epss

{'score': 0.00444}


Wed, 18 Jun 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Php
Php php
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
Vendors & Products Php
Php php

Thu, 13 Feb 2025 18:00:00 +0000

Type Values Removed Values Added
Description In PHP 8.3.* before 8.3.5, function mb_encode_mimeheader() runs endlessly for some inputs that contain long strings of non-space characters followed by a space. This could lead to a potential DoS attack if a hostile user sends data to an application that uses this function.  In PHP 8.3.* before 8.3.5, function mb_encode_mimeheader() runs endlessly for some inputs that contain long strings of non-space characters followed by a space. This could lead to a potential DoS attack if a hostile user sends data to an application that uses this function.

cve-icon MITRE

Status: PUBLISHED

Assigner: php

Published:

Updated: 2025-02-13T17:46:31.192Z

Reserved: 2024-03-21T05:32:12.866Z

Link: CVE-2024-2757

cve-icon Vulnrichment

Updated: 2024-08-01T19:25:41.969Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-29T04:15:08.113

Modified: 2025-06-18T21:11:40.787

Link: CVE-2024-2757

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-04-12T00:00:00Z

Links: CVE-2024-2757 - Bugzilla

cve-icon OpenCVE Enrichment

No data.