cbcvebase.
CVE-2016-1546
published 2016-07-06

CVE-2016-1546: The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection…

PriorityP334medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
15.33%
96.4th percentile
The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows.

Affected

4 ranges
VendorProductVersion rangeFixed in
apachehttp_server
apachehttp_server
apachehttpd
debianapache2< apache2 2.4.20-1 (bookworm)apache2 2.4.20-1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • The attack manipulates HTTP/2 flow-control windows on streams to block server worker threads, causing thread starvation. Detect anomalous HTTP/2 connections where flow-control window updates are manipulated to hold streams open indefinitely without data transfer.
  • Target environment: Apache HTTP Server with mod_http2 enabled, versions 2.4.17 and 2.4.18. Detection should focus on these specific versions running HTTP/2.
  • Monitor for a single HTTP/2 connection spawning an unusually high number of simultaneous stream workers, which is the root cause of the thread starvation condition.
  • ·Vulnerability only affects Apache HTTP Server with mod_http2 enabled. Systems running 2.4.17 or 2.4.18 without mod_http2 are not affected.
  • ·Fixed in Apache HTTP Server 2.4.20. Systems already on 2.4.20 or later are not vulnerable.
  • ·All Red Hat Enterprise Linux 5, 6, and 7 packages for httpd are listed as Not Affected, so detections targeting RHEL environments may not be relevant.
  • ·The upstream fix was committed via SVN revision 1733727 and backported to the 2.4.x branch via revision 1734413; it was included in 2.4.19 (unreleased) and shipped in 2.4.20.

CVSS provenance

nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vendor_redhat8.8HIGH
vendor_apache5.9LOW
vendor_debian5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.