mod_http2 is vulnerable to Resource Exhaustion
75
High Risk
mod_http2 merges split HTTP/2 Cookie header fields but does not count merged cookie crumbs against LimitRequestFields. A client can send many HPACK-indexed cookie fragments and stall the response stream, causing Apache to repeatedly rebuild and retain large header allocations. Pre-fix servers can suffer remote memory exhaustion and availability loss through HTTP/2 requests. The fix treats merged cookie headers as added fields so they are limited by LimitRequestFields.
You are affected if you are using a version that falls within the vulnerable range.
mod_http2 is vulnerable to Resource Exhaustion in versions 2.0.0 - 2.0.40.
Upgrade the mod_http2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant