Impact
The UnrealIRCd webserver does not limit the number of HTTP request headers, allowing a remote attacker to send a request with an unlimited number of headers when a websocket or JSON‑RPC listener is enabled. The server then consumes increasing memory until it becomes unresponsive, resulting in a denial of service that can affect the availability of the entire IRC network. The flaw is a resource exhaustion weakness (CWE‑770).
Affected Systems
UnrealIRCd versions 6.0.5 through 6.2.6, all releases before 6.2.7 are vulnerable. The vulnerability manifests when the webserver component is enabled with websocket or JSON‑RPC listener options; those listeners are disabled by default.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. The EPSS score is less than 1%, indicating a low but nonzero likelihood of exploitation, but this does not diminish the overall risk; the flaw is remotely exploitable via HTTP and is known to be discussed in the UnrealIRCd forums. The vulnerability is not yet in CISA’s KEV catalogue, but should be treated as a high‑priority issue because the exploit requires only an HTTP connection to the vulnerable host.
OpenCVE Enrichment