UnrealIRCd vulnerability

The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request with an unlimited number of headers, if a websocket or JSON-RPC listener is enabled (disabled by default).

Published 13 Sep 2026Updated 13 Sep 20262 sources
CVSS 8.7

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.