CVE-2016-1546
published 2016-07-06CVE-2016-1546: The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection…
PriorityP334medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
15.33%
96.4th percentile
The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | httpd | — | — |
| debian | apache2 | < apache2 2.4.20-1 (bookworm) | apache2 2.4.20-1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →The attack manipulates HTTP/2 flow-control windows on streams to block server worker threads, causing thread starvation. Detect anomalous HTTP/2 connections where flow-control window updates are manipulated to hold streams open indefinitely without data transfer. ↗
- →Target environment: Apache HTTP Server with mod_http2 enabled, versions 2.4.17 and 2.4.18. Detection should focus on these specific versions running HTTP/2. ↗
- →Monitor for a single HTTP/2 connection spawning an unusually high number of simultaneous stream workers, which is the root cause of the thread starvation condition. ↗
- ·Vulnerability only affects Apache HTTP Server with mod_http2 enabled. Systems running 2.4.17 or 2.4.18 without mod_http2 are not affected. ↗
- ·Fixed in Apache HTTP Server 2.4.20. Systems already on 2.4.20 or later are not vulnerable. ↗
- ·All Red Hat Enterprise Linux 5, 6, and 7 packages for httpd are listed as Not Affected, so detections targeting RHEL environments may not be relevant. ↗
- ·The upstream fix was committed via SVN revision 1733727 and backported to the 2.4.x branch via revision 1734413; it was included in 2.4.19 (unreleased) and shipped in 2.4.20. ↗
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vendor_redhat8.8HIGH
vendor_apache5.9LOW
vendor_debian5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f6fj-787v-v59m: The Apache HTTP Server 2
ghsa_unreviewed·2022-05-13
CVE-2016-1546 [MEDIUM] GHSA-f6fj-787v-v59m: The Apache HTTP Server 2
The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows.
OSV
CVE-2016-1546: The Apache HTTP Server 2
osv·2016-07-06·CVSS 5.9
CVE-2016-1546 [MEDIUM] CVE-2016-1546: The Apache HTTP Server 2
The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows.
Red Hat
libtiff: Out-of-bounds write in PixarLogDecode() function in tif_pixarlog.c
vendor_redhat·2016-06-15·CVSS 8.8
CVE-2016-5320 [HIGH] CWE-787 libtiff: Out-of-bounds write in PixarLogDecode() function in tif_pixarlog.c
libtiff: Out-of-bounds write in PixarLogDecode() function in tif_pixarlog.c
[REJECTED CVE] This CVE has been rejected. This candidate is a duplicate of CVE-2016-5314. Note: All CVE users should reference CVE-2016-5314 instead of this candidate.
Statement: Also, please note that, this issue has already been addressed in Red Hat Enterprise Linux 6 via RHSA-2016:1547 and in Red Hat Enterprise Linux 7 via RHSA-2016:1546 as listed under affected packages and Security Errata.
Package: libtiff (Red Hat Enterprise Linux 5) - Will not fix
Package: compat-libtiff3 (Red Hat Enterprise Linux 7) - Not affected
Red Hat
httpd: mod_http2 denial-of-service by thread starvation
vendor_redhat·2016-04-11·CVSS 5.9
CVE-2016-1546 [MEDIUM] httpd: mod_http2 denial-of-service by thread starvation
httpd: mod_http2 denial-of-service by thread starvation
The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows.
A denial of service flaw was found in httpd's mod_http2 module. A remote attacker could use this flaw to block server threads for long times, causing starvation of worker threads, by manipulating the flow control windows on streams.
Package: httpd (CloudForms Management Engine 5) - Not affected
Package: httpd (Red Hat Directory Server 8) - Not affected
Package: httpd (Red Hat Enterprise Linux 5) - Not affected
Package: httpd (Red Hat Enterprise Linux 6) -
Debian
CVE-2016-1546: apache2 - The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not li...
vendor_debian·2016·CVSS 5.9
CVE-2016-1546 [MEDIUM] CVE-2016-1546: apache2 - The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not li...
The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows.
Scope: local
bookworm: resolved (fixed in 2.4.20-1)
bullseye: resolved (fixed in 2.4.20-1)
forky: resolved (fixed in 2.4.20-1)
sid: resolved (fixed in 2.4.20-1)
trixie: resolved (fixed in 2.4.20-1)
Apache
Apache httpd: CVE-2016-1546
vendor_apache·CVSS 5.9
CVE-2016-1546 [LOW] Apache httpd: CVE-2016-1546
Apache httpd: CVE-2016-1546
By manipulating the flow control windows on streams, a client was able to block server threads for long times, causing starvation of worker threads. Connections could still be opened, but no streams where processed for these. This issue affected HTTP/2 support in 2.4.17 and 2.4.18. Acknowledgements: This issue was reported by Noam Mazor. Reported to security team 2016-02-02 Issue public 2016-04-11 Update 2.4.20 released 2016-04-11 Affects 2.4.18, 2.4.17
Severity: low
No detection rules found.
No public exploits indexed.
Hackernews
New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
blogs_hackernews·2026-06-03·CVSS 7.5
CVE-2016-6581 [HIGH] New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora.
The vulnerability has been codenamed HTTP/2 Bomb by Calif.
"The vulnerable behavior exists in each server's default HTTP/2 configuration," the company said, adding it was discovered by OpenAI Codex by chaining together two known techniques: a compression bomb and a Slowloris -style hold.
"The bomb targets HPACK, HTTP/2's header compression scheme: one
Bugzilla
CVE-2016-1546 httpd: httpd24: Denial-of-service by thread starvation [fedora-all]
bugzilla·2016-05-16·CVSS 5.9
CVE-2016-1546 [MEDIUM] CVE-2016-1546 httpd: httpd24: Denial-of-service by thread starvation [fedora-all]
CVE-2016-1546 httpd: httpd24: Denial-of-service by thread starvation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2016-1546 httpd: mod_http2 denial-of-service by thread starvation
bugzilla·2016-05-16·CVSS 5.9
CVE-2016-1546 [MEDIUM] CVE-2016-1546 httpd: mod_http2 denial-of-service by thread starvation
CVE-2016-1546 httpd: mod_http2 denial-of-service by thread starvation
A vulnerability was found in httpd. By manipulating the flow control windows on streams, a client was able to block server threads for long times, causing starvation of worker threads. Connections could still be opened, but no streams where processed for these. This issue affected HTTP/2 support in 2.4.17 and 2.4.18.
External references:
http://httpd.apache.org/security/vulnerabilities_24.html
Discussion:
Created httpd tracking bugs for this issue:
Affects: fedora-all [bug 1336351]
---
Upstream commit:
http://svn.apache.org/viewvc?view=revision&revision=1733727
Backported to 2.4.x branch via:
http://svn.apache.org/viewvc?view=revision&revision=1734413
Included in 2.4.19, which was not released.
---
This iss
Bugzilla
CVE-2016-3945 libtiff: out-of-bounds write in the tiff2rgba tool
bugzilla·2016-04-08·CVSS 7.8
CVE-2016-3945 [HIGH] CVE-2016-3945 libtiff: out-of-bounds write in the tiff2rgba tool
CVE-2016-3945 libtiff: out-of-bounds write in the tiff2rgba tool
Out-of-bounds write vulnerability was found in cvt_by_strip and cvt_by_tile functions in tiff2rgba, allowing attacker to cause a denial of service or command execution via a crafted TIFF image.
Public via:
http://seclists.org/oss-sec/2016/q2/30
Upstream bug:
http://bugzilla.maptools.org/show_bug.cgi?id=2545
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1547 https://rhn.redhat.com/errata/RHSA-2016-1547.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1546 https://rhn.redhat.com/errata/RHSA-2016-1546.html
---
It would have been good to attach your patch to the upstream bug instead of letting l
Bugzilla
CVE-2015-8784 libtiff: out-of-bound write in NeXTDecode()
bugzilla·2016-01-25·CVSS 6.5
CVE-2015-8784 [MEDIUM] CVE-2015-8784 libtiff: out-of-bound write in NeXTDecode()
CVE-2015-8784 libtiff: out-of-bound write in NeXTDecode()
A flaw was discovered in a way libtiff decodes special data. A potential out-of-bounds write could occur for specifically crafted images.
External bug report:
http://bugzilla.maptools.org/show_bug.cgi?id=2508
CVE assignment:
http://seclists.org/oss-sec/2016/q1/191
Upstream fix:
https://github.com/vadz/libtiff/commit/b18012dae552f85dcc5c57d3bf4e997a15b1cc1c
Discussion:
Created libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1301653]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1547 https://rhn.redhat.com/errata/RHSA-2016-1547.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1546 https://r
Bugzilla
CVE-2015-8665 libtiff: Out-of-bounds read in tif_getimage.c
bugzilla·2015-12-28·CVSS 5.5
CVE-2015-8665 [MEDIUM] CVE-2015-8665 libtiff: Out-of-bounds read in tif_getimage.c
CVE-2015-8665 libtiff: Out-of-bounds read in tif_getimage.c
An Out-of-bounds read flaw was found in libtiff. An attacker could create a specially-crafted TIFF file, which could cause libtiff to crash.
Reference:
http://www.openwall.com/lists/oss-security/2015/12/24/4
Discussion:
Please inform me when you will have a patch or at least a reference for the bugzilla.
Greetings
Petr
---
Patch for this and bug#1294427:
https://github.com/vadz/libtiff/commit/f94a29a822f5528d2334592760fbb7938f15eb55
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1547 https://rhn.redhat.com/errata/RHSA-2016-1547.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1546 https://rhn.redhat.com/
Bugzilla
CVE-2015-8668 libtiff: OOB read in bmp2tiff
bugzilla·2015-12-28·CVSS 9.8
CVE-2015-8668 [CRITICAL] CVE-2015-8668 libtiff: OOB read in bmp2tiff
CVE-2015-8668 libtiff: OOB read in bmp2tiff
A heap-buffer oveflow was found in bmp2tiff, A tool used to created TIFF format files from BMP format image files. An attacker could provide a specially-crafted BMP format file, which when converted to TIFF format, using the bmp2tiff tool, could lead to bmp2tiff executable to crash.
Reference:
http://seclists.org/bugtraq/2015/Dec/138
Discussion:
I haven't completed my analysis yet, but for now I tend to say that this is only OOB read.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1547 https://rhn.redhat.com/errata/RHSA-2016-1547.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1546 https://rhn.redhat.com/errata/RHSA-2016-
Bugzilla
CVE-2015-8683 libtiff: Out-of-bounds when reading CIE Lab image format files
bugzilla·2015-12-28·CVSS 5.5
CVE-2015-8683 [MEDIUM] CVE-2015-8683 libtiff: Out-of-bounds when reading CIE Lab image format files
CVE-2015-8683 libtiff: Out-of-bounds when reading CIE Lab image format files
An out-bounds-read flaw was found in the way libtiff processed CIE Lab image format files. A attacker could create a specially-crafted CIE Lab image format files which could cause libtiff to crash.
Reference:
http://seclists.org/oss-sec/2015/q4/583
Discussion:
Patch for this and bug#1294444:
https://github.com/vadz/libtiff/commit/f94a29a822f5528d2334592760fbb7938f15eb55
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1547 https://rhn.redhat.com/errata/RHSA-2016-1547.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1546 https://rhn.redhat.com/errata/RHSA-2016-1546.html
Bugzilla
CVE-2015-7554 libtiff: Invalid-write in _TIFFVGetField() when parsing some extension tags
bugzilla·2015-12-28·CVSS 9.8
CVE-2015-7554 [CRITICAL] CVE-2015-7554 libtiff: Invalid-write in _TIFFVGetField() when parsing some extension tags
CVE-2015-7554 libtiff: Invalid-write in _TIFFVGetField() when parsing some extension tags
An Invalid memory write flaw was found in libtiff in the way it parsed certain extension tags when reading TIFF format files. An attacker could use this flaw to crash or even execute arbitrary code with the permission of the user running such an application compiled against libtiff.
Reference:
http://seclists.org/bugtraq/2015/Dec/137
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1547 https://rhn.redhat.com/errata/RHSA-2016-1547.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1546 https://rhn.redhat.com/errata/RHSA-2016-1546.html
---
*** Bug 1410063 has been marked as
http://httpd.apache.org/security/vulnerabilities_24.htmlhttp://svn.apache.org/viewvc?view=revision&revision=1733727http://www.apache.org/dist/httpd/CHANGES_2.4http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.htmlhttp://www.securityfocus.com/bid/92331https://access.redhat.com/errata/RHSA-2017:1161https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r04e89e873d54116a0635ef2f7061c15acc5ed27ef7500997beb65d6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rb14daf9cc4e28d18cdc15d6a6ca74e565672fabf7ad89541071d008b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re1e3a24664d35bcd0a0e793e0b5fc6ca6c107f99a1b2c545c5d4b467%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://security.gentoo.org/glsa/201610-02https://security.netapp.com/advisory/ntap-20180601-0001/http://httpd.apache.org/security/vulnerabilities_24.htmlhttp://svn.apache.org/viewvc?view=revision&revision=1733727http://www.apache.org/dist/httpd/CHANGES_2.4http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.htmlhttp://www.securityfocus.com/bid/92331https://access.redhat.com/errata/RHSA-2017:1161https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r04e89e873d54116a0635ef2f7061c15acc5ed27ef7500997beb65d6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rb14daf9cc4e28d18cdc15d6a6ca74e565672fabf7ad89541071d008b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re1e3a24664d35bcd0a0e793e0b5fc6ca6c107f99a1b2c545c5d4b467%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://security.gentoo.org/glsa/201610-02https://security.netapp.com/advisory/ntap-20180601-0001/
2016-07-06
Published