THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-hr6j-w4mw-g9mj (high) — alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server

[GHSA] GHSA-hr6j-w4mw-g9mj (high) — alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server

medgithub_advisoriesPublished 2026-08-28

GHSA-hr6j-w4mw-g9mj Severity: high CVE: CVE-2026-55484

alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server

### Summary A single unauthenticated HTTP request to a path starting with `?` (e.g. `GET ? HTTP/1.1`) crashes the entire server process. The request line parser passes the path to `sanitizeReq

Indicators of compromise

Original source: https://github.com/advisories/GHSA-hr6j-w4mw-g9mj