Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to UnrealIRCd 6.2.7 or later. Alternatively, apply the hot-patch to fix the issue without restart: ./unrealircd hot-patch webserver-header-dos
Vendor Workaround
Remove the websocket and rpc options from your listen blocks until the patch or upgrade is applied.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 13 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | UnrealIRCd Webserver Header DoS via Unlimited HTTP Headers |
Sun, 13 Sep 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request with an unlimited number of headers, if a websocket or JSON-RPC listener is enabled (disabled by default). | |
| First Time appeared |
Unrealircd
Unrealircd unrealircd |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:2.3:a:unrealircd:unrealircd:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Unrealircd
Unrealircd unrealircd |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-13T02:00:54.190Z
Reserved: 2026-09-13T02:00:53.718Z
Link: CVE-2026-90668
No data.
Status : Received
Published: 2026-09-13T02:17:05.103
Modified: 2026-09-13T02:17:05.103
Link: CVE-2026-90668
No data.
OpenCVE Enrichment
Updated: 2026-09-13T12:15:05Z
-
CWE-770
Allocation of Resources Without Limits or Throttling