Impact
A malformed HTTP chunked body can trigger an infinite loop in React\Http\Io\ChunkedDecoder. The decoder repeatedly processes the same unshrunk buffer, consuming excessive CPU and causing the affected component to hang. The result is a denial‑of‑service, either by freezing a server handling requests or a client receiving a response.
Affected Systems
ReactPHP’s http package, across all components that use ChunkedDecoder – including the HttpServer and Browser clients – is affected in versions from 0.6.0 through 1.11.1. Users running any of these releases are at risk.
Risk and Exploitability
Based on the description, it is inferred that the flaw can be triggered by any remote party that can send a crafted HTTP request. The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests real‑world exploitation is unlikely. Because the attack relies on transmitting malformed chunked bodies, the vector is network‑based. The vulnerability is not listed in CISA’s KEV catalog, meaning no known widespread exploitation has been confirmed.
OpenCVE Enrichment
Github GHSA