CVE-2018-1333
published 2018-06-18CVE-2018-1333: By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed…
PriorityP346high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
17.10%
96.7th percentile
By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
| apache | http_server | 2.4.18 – 2.4.30 | — |
| apache_software_foundation | apache_http_server | — | — |
| canonical | ubuntu_linux | — | — |
| debian | apache2 | < apache2 2.4.34-1 (bookworm) | apache2 2.4.34-1 (bookworm) |
| highcharts | highcharts | >= 0 < 6.1.0 | 6.1.0 |
| marked_project | marked | >= 0 < 0.3.17 | 0.3.17 |
| mel-spintax_project | mel-spintax | >= 0 < 1.0.3 | 1.0.3 |
| protobufjs_project | protobufjs | >= 0 < 5.0.3 | 5.0.3 |
| protobufjs_project | protobufjs | >= 6.0.0 < 6.8.6 | 6.8.6 |
| redhat | jboss_core_services | — | — |
| rgb2hex_project | rgb2hex | >= 0 < 0.1.6 | 0.1.6 |
| segmentio | is-url | >= 0 < 1.2.3 | 1.2.3 |
| skeemas_project | skeemas | >= 0 < 1.2.5 | 1.2.5 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Marked allows Regular Expression Denial of Service (ReDoS) attacks
ghsa·2025-05-23
CVE-2018-25110 [MEDIUM] CWE-1333 Marked allows Regular Expression Denial of Service (ReDoS) attacks
Marked allows Regular Expression Denial of Service (ReDoS) attacks
Marked prior to version 0.3.17 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to catastrophic backtracking in several regular expressions used for parsing HTML tags and markdown links. An attacker can exploit this vulnerability by providing specially crafted markdown input, such as deeply nested or repetitively structured brackets or tag attributes, which cause the parser to hang and lead to a Denial of Service.
GHSA
is-url Inefficient Regular Expression Complexity vulnerability
ghsa·2023-02-04
CVE-2018-25079 [HIGH] CWE-1333 is-url Inefficient Regular Expression Complexity vulnerability
is-url Inefficient Regular Expression Complexity vulnerability
A vulnerability was found in Segmentio is-url up to 1.2.2. It has been rated as problematic. Affected by this issue is an unknown functionality of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. Upgrading to version 1.2.3 is able to address this issue. The name of the patch is 149550935c63a98c11f27f694a7c4a9479e53794. It is recommended to upgrade the affected component. VDB-220058 is the identifier assigned to this vulnerability.
GHSA
mel-spintax has Inefficient Regular Expression Complexity
ghsa·2023-01-18
CVE-2018-25077 [MEDIUM] CWE-1333 mel-spintax has Inefficient Regular Expression Complexity
mel-spintax has Inefficient Regular Expression Complexity
A vulnerability was found in melnaron mel-spintax. It has been rated as problematic. Affected by this issue is some unknown functionality of the file `lib/spintax.js`. The manipulation of the argument text leads to inefficient regular expression complexity. The name of the patch is 37767617846e27b87b63004e30216e8f919637d3. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-218456.
GHSA
skeemas Inefficient Regular Expression Complexity vulnerability
ghsa·2023-01-11
CVE-2018-25074 [HIGH] CWE-1333 skeemas Inefficient Regular Expression Complexity vulnerability
skeemas Inefficient Regular Expression Complexity vulnerability
A vulnerability was found in Prestaul skeemas and classified as problematic. This issue affects some unknown processing of the file validators/base.js. The manipulation of the argument uri leads to inefficient regular expression complexity. The name of the patch is 65e94eda62dc8dc148ab3e59aa2ccc086ac448fd. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218003.
GHSA
rgb2hex vulnerable to inefficient regular expression complexity
ghsa·2022-12-31
CVE-2018-25061 [HIGH] CWE-1333 rgb2hex vulnerable to inefficient regular expression complexity
rgb2hex vulnerable to inefficient regular expression complexity
A vulnerability was found in rgb2hex up to 0.1.5. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to inefficient regular expression complexity. The attack may be initiated remotely. Upgrading to version 0.1.6 can address this issue. The name of the patch is 9e0c38594432edfa64136fdf7bb651835e17c34f. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217151.
GHSA
email-existence Inefficient Regular Expression Complexity vulnerability
ghsa·2022-12-27
CVE-2018-25049 [HIGH] CWE-1333 email-existence Inefficient Regular Expression Complexity vulnerability
email-existence Inefficient Regular Expression Complexity vulnerability
A vulnerability was found in email-existence. It has been rated as problematic. Affected by this issue is some unknown functionality of the file `index.js`. The manipulation leads to inefficient regular expression complexity. The name of the patch is 0029ba71b6ad0d8ec0baa2ecc6256d038bdd9b56. It is recommended to apply a patch to fix this issue. VDB-216854 is the identifier assigned to this vulnerability.
GHSA
GHSA-885g-r558-qx2m: By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of servi
ghsa_unreviewed·2022-05-13
CVE-2018-1333 [HIGH] CWE-400 GHSA-885g-r558-qx2m: By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of servi
By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).
GHSA
Regular Expression Denial of Service in highcharts
ghsa·2019-03-18
CVE-2018-20801 [HIGH] CWE-1333 Regular Expression Denial of Service in highcharts
Regular Expression Denial of Service in highcharts
Versions of `highcharts` prior to 6.1.0 are vulnerable to Regular Expression Denial of Service (ReDoS). Untrusted input may cause catastrophic backtracking while matching regular expressions. This can cause the application to be unresponsive leading to Denial of Service.
## Recommendation
Upgrade to version 6.1.0 or higher.
GHSA
Denial of Service in protobufjs
ghsa·2018-10-09
CVE-2018-3738 [MEDIUM] CWE-1333 Denial of Service in protobufjs
Denial of Service in protobufjs
Versions of `protobufjs` before 5.0.3 and 6.8.6 are vulnerable to a regular expression denial of service when parsing crafted invalid *.proto files.
## Recommendation
Update to version 5.0.3, 6.8.6 or later.
OSV
apache2 vulnerabilities
osv·2018-10-03·CVSS 5.9
CVE-2018-1302 [MEDIUM] apache2 vulnerabilities
apache2 vulnerabilities
Robert Swiecki discovered that the Apache HTTP Server HTTP/2 module
incorrectly destroyed certain streams. A remote attacker could possibly
use this issue to cause the server to crash, leading to a denial of
service. (CVE-2018-1302)
Craig Young discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled certain requests. A remote attacker could possibly
use this issue to cause the server to consume resources, leading to a
denial of service. (CVE-2018-1333)
Gal Goldshtein discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled large SETTINGS frames. A remote attacker could possibly
use this issue to cause the server to consume resources, leading to a
denial of service. (CVE-2018-11763)
OSV
CVE-2018-1333: By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of servi
osv·2018-06-18·CVSS 7.5
CVE-2018-1333 [HIGH] CVE-2018-1333: By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of servi
By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).
Red Hat
is-url: inefficient regular expression complexity
vendor_redhat·2023-02-04·CVSS 4.3
CVE-2018-25079 [MEDIUM] CWE-1333 is-url: inefficient regular expression complexity
is-url: inefficient regular expression complexity
A vulnerability was found in Segmentio is-url up to 1.2.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. Upgrading to version 1.2.3 is able to address this issue. The patch is identified as 149550935c63a98c11f27f694a7c4a9479e53794. It is recommended to upgrade the affected component. VDB-220058 is the identifier assigned to this vulnerability.
A flaw was found in the is-url package. The manipulation leads to inefficient regular expression complexity.
Package: openshift3/ose-console (Red Hat OpenShift Container Platform 3.11) - Out of support scope
Package: openshift4/ose
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2018-10-03·CVSS 5.9
CVE-2018-11763 [MEDIUM] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in the Apache HTTP Server.
Robert Swiecki discovered that the Apache HTTP Server HTTP/2 module
incorrectly destroyed certain streams. A remote attacker could possibly
use this issue to cause the server to crash, leading to a denial of
service. (CVE-2018-1302)
Craig Young discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled certain requests. A remote attacker could possibly
use this issue to cause the server to consume resources, leading to a
denial of service. (CVE-2018-1333)
Gal Goldshtein discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled large SETTINGS frames. A remote attacker could possibly
use this issue to cause the server to consume resources, leading
Red Hat
httpd: mod_http2: Too much time allocated to workers, possibly leading to DoS
vendor_redhat·2018-07-18·CVSS 7.5
CVE-2018-1333 [HIGH] CWE-400 httpd: mod_http2: Too much time allocated to workers, possibly leading to DoS
httpd: mod_http2: Too much time allocated to workers, possibly leading to DoS
By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).
Package: httpd (Red Hat Enterprise Linux 6) - Not affected
Package: httpd (Red Hat Enterprise Linux 7) - Not affected
Package: mod_http2 (Red Hat Enterprise Linux 8) - Not affected
Package: httpd (Red Hat JBoss Enterprise Application Platform 5) - Not affected
Package: httpd (Red Hat JBoss Enterprise Application Platform 6) - Not affected
Package: httpd (Red Hat JBoss Enterprise Web Server 2) - Not affected
Package: httpd (Red Hat JBoss Web Server 3) - Not affected
Package: httpd (Red H
Red Hat
nodejs-braces: Regular Expression Denial of Service (ReDoS) in lib/parsers.js
vendor_redhat·2018-02-19·CVSS 5.3
CVE-2018-1109 [MEDIUM] CWE-1333 nodejs-braces: Regular Expression Denial of Service (ReDoS) in lib/parsers.js
nodejs-braces: Regular Expression Denial of Service (ReDoS) in lib/parsers.js
A vulnerability was found in Braces versions 2.2.0 and above, prior to 2.3.1. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) attacks.
A vulnerability was found in nodejs-braces. Affected versions of this package are vulnerable to Regular expression Denial of Service (ReDoS) attacks. The highest threat from this vulnerability is system availability.
Statement: Red Hat Quay includes braces as a dependency of webpack. Braces is only used at build time, not at runtime, reducing the impact of this vulnerability to low.
Package: nodejs-braces (Red Hat Mobile Application Platform 4) - Not affected
Package: nodejs-braces (Red Hat OpenShift Enterprise 3) - Not affecte
Debian
CVE-2018-1333: apache2 - By specially crafting HTTP/2 requests, workers would be allocated 60 seconds lon...
vendor_debian·2018·CVSS 7.5
CVE-2018-1333 [HIGH] CVE-2018-1333: apache2 - By specially crafting HTTP/2 requests, workers would be allocated 60 seconds lon...
By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).
Scope: local
bookworm: resolved (fixed in 2.4.34-1)
bullseye: resolved (fixed in 2.4.34-1)
forky: resolved (fixed in 2.4.34-1)
sid: resolved (fixed in 2.4.34-1)
trixie: resolved (fixed in 2.4.34-1)
No detection rules found.
No public exploits indexed.
HackerOne
DoS for HTTP/2 connections by crafted requests (CVE-2018-1333)
hackerone·2018-10-28·CVSS 7.5
CVE-2018-1333 [HIGH] DoS for HTTP/2 connections by crafted requests (CVE-2018-1333)
DoS for HTTP/2 connections by crafted requests (CVE-2018-1333)
mod_http2 can be tricked by specially crafted requests to hold server resources longer than necessary.
A simple demonstration of this for a server with h2c enabled is as follows:
for x in `seq 0 500`; do echo 505249202a20485454502f322e300d0a0d0a534d0d0a0d0a00001204000000000000000000006400044000000000020000000000001b0104000000018284864187089d5c0b8178ff7a8825b650c3abb6f2e053032a2f2a00001b0105000000019a84864187089d5c0b8178ff7a880000000000000000 | xxd -r -p | nc hostname port 2>&1 >/dev/null & done
## Impact
Certain crafted HTTP2 requests identified with afl-fuzz can cause Apache worker threads to stay open waiting for data until a timeout. A typical configuration has a 1 minute timeout with 150 request workers. This means an a
Bugzilla
CVE-2018-1333 httpd: mod_http2: too much time allocated to workers, possibly leading to DoS [fedora-all]
bugzilla·2018-07-20·CVSS 7.5
CVE-2018-1333 [HIGH] CVE-2018-1333 httpd: mod_http2: too much time allocated to workers, possibly leading to DoS [fedora-all]
CVE-2018-1333 httpd: mod_http2: too much time allocated to workers, possibly leading to DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2018-1333 httpd: mod_http2: Too much time allocated to workers, possibly leading to DoS
bugzilla·2018-07-20·CVSS 7.5
CVE-2018-1333 [HIGH] CVE-2018-1333 httpd: mod_http2: Too much time allocated to workers, possibly leading to DoS
CVE-2018-1333 httpd: mod_http2: Too much time allocated to workers, possibly leading to DoS
Apache httpd before version 2.4.34 has a vulnerability in the handling of specially crafted HTTP/2 requests, causing workers to be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service.
This issue only affects servers that have configured and enabled HTTP/2 support, which is not the default
External References:
https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2018-1333
Discussion:
Created httpd tracking bugs for this issue:
Affects: fedora-all [bug 1605049]
---
HTTP/2 support was first added upstream in version 2.4.17:
https://httpd.apache.org/docs/2.4/mod/mod_http2.html
http://archive.apache.org/dist/httpd/CHANGES_2.4.17
Hence earl
http://www.securitytracker.com/id/1041402https://access.redhat.com/errata/RHSA-2018:3558https://access.redhat.com/errata/RHSA-2019:0366https://access.redhat.com/errata/RHSA-2019:0367https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2018-1333https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935e2a0a6876dad3c%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd2fb621142e7fa187cfe12d7137bf66e7234abcbbcd800074c84a538%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re473305a65b4db888e3556e4dae10c2a04ee89dcff2e26ecdbd860a9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20180926-0007/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03909en_ushttps://usn.ubuntu.com/3783-1/https://www.tenable.com/security/tns-2019-09http://www.securitytracker.com/id/1041402https://access.redhat.com/errata/RHSA-2018:3558https://access.redhat.com/errata/RHSA-2019:0366https://access.redhat.com/errata/RHSA-2019:0367https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2018-1333https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935e2a0a6876dad3c%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd2fb621142e7fa187cfe12d7137bf66e7234abcbbcd800074c84a538%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re473305a65b4db888e3556e4dae10c2a04ee89dcff2e26ecdbd860a9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20180926-0007/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03909en_ushttps://usn.ubuntu.com/3783-1/https://www.tenable.com/security/tns-2019-09
2018-06-18
Published