httpd is vulnerable to Resource Exhaustion
75
High Risk
Apache httpd's bundled HTTP/2 implementation can merge split Cookie header fields without counting each crumb against the configured request-field limit. A client can combine HPACK indexed cookie fragments with a stalled response stream to keep large header allocations live. Affected servers can suffer remote memory exhaustion and availability loss through HTTP/2 requests. No Apache httpd 2.4.x release containing the fix was available in the checked evidence.
You are affected if you are using a version that falls within the vulnerable range and HTTP/2 is enabled.
httpd is vulnerable to Resource Exhaustion in versions 2.4.17 - 2.4.67.
Disable HTTP/2 by setting Protocols http/1.1 until a patched Apache httpd release is available.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant