Description
react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, React\Http\Io\ChunkedDecoder could enter an infinite loop while processing a malformed Transfer-Encoding: chunked body because handleData required its buffer to shrink on every iteration. An incomplete terminal-chunk trailer without CRLF left the buffer unchanged after strpos returned false, and exactly two non-CRLF bytes after a completed non-terminal chunk bypassed both the error and wait guards. The affected decoder processes request bodies for React\Http\HttpServer and response bodies for React\Http\Browser, allowing a malicious client to freeze a server or a malicious or compromised server to freeze a client. A reverse proxy that normalizes inbound requests may protect the server direction but does not protect outbound Browser requests. This issue is fixed in version 1.11.1.
Published: 2026-09-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via CPU exhaustion
Action: Patch
AI Analysis

Impact

A malformed HTTP chunked body can trigger an infinite loop in React\Http\Io\ChunkedDecoder. The decoder repeatedly processes the same unshrunk buffer, consuming excessive CPU and causing the affected component to hang. The result is a denial‑of‑service, either by freezing a server handling requests or a client receiving a response.

Affected Systems

ReactPHP’s http package, across all components that use ChunkedDecoder – including the HttpServer and Browser clients – is affected in versions from 0.6.0 through 1.11.1. Users running any of these releases are at risk.

Risk and Exploitability

Based on the description, it is inferred that the flaw can be triggered by any remote party that can send a crafted HTTP request. The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests real‑world exploitation is unlikely. Because the attack relies on transmitting malformed chunked bodies, the vector is network‑based. The vulnerability is not listed in CISA’s KEV catalog, meaning no known widespread exploitation has been confirmed.

Generated by OpenCVE AI on September 18, 2026 at 03:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade react/http to version 1.11.1 or later, which contains the fixed ChunkedDecoder.
  • If you use a reverse proxy, configure it to validate and normalize Transfer‑Encoding headers to protect server‑side server requests.
  • If upgrading is not immediately possible, configure your firewall or ingress to reject malformed chunked requests, or apply a custom decoder guard to detect infinite loops.

Generated by OpenCVE AI on September 18, 2026 at 03:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-x424-64qh-5j54 react/http: A malformed HTTP chunked body can lead to a denial-of-service and peg the CPU
History

Thu, 17 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Reactphp
Reactphp http
Vendors & Products Reactphp
Reactphp http

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, React\Http\Io\ChunkedDecoder could enter an infinite loop while processing a malformed Transfer-Encoding: chunked body because handleData required its buffer to shrink on every iteration. An incomplete terminal-chunk trailer without CRLF left the buffer unchanged after strpos returned false, and exactly two non-CRLF bytes after a completed non-terminal chunk bypassed both the error and wait guards. The affected decoder processes request bodies for React\Http\HttpServer and response bodies for React\Http\Browser, allowing a malicious client to freeze a server or a malicious or compromised server to freeze a client. A reverse proxy that normalizes inbound requests may protect the server direction but does not protect outbound Browser requests. This issue is fixed in version 1.11.1.
Title react/http: A malformed HTTP chunked body can lead to a denial-of-service and peg the CPU
Weaknesses CWE-835
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T14:46:47.220Z

Reserved: 2026-09-02T18:12:13.535Z

Link: CVE-2026-84997

cve-icon Vulnrichment

Updated: 2026-09-16T14:46:19.854Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T15:18:00.863

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-84997

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:15:02Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')