Intel

AIKIDO-2024-10307

laravel/octane is vulnerable to DoS

DoS Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 1, 2024

71

High Risk

This Affects:

phplaravel/octane
0.1.0 - 2.5.5
Fixed in 2.5.6
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to Denial of Service (DoS). Memory leaks or excessive memory retention occur, particularly during high-volume or large request processing in Laravel Octane when using the Swoole server (ConvertSwooleRequestToIlluminateRequest.php).

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges and you are using the Swoole server.

Background info

laravel/octane is vulnerable to DoS in versions 0.1.0 - 2.5.5.

How to fix this

Upgrade the laravel/octane library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform