CVE-2021-31618
published 2021-06-15CVE-2021-31618: Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used…
PriorityP355high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
51.21%
98.8th percentile
Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used for the HTTP/1 protocol as well. On violation of these restrictions and HTTP response is sent to the client with a status code indicating why the request was rejected. This rejection response was not fully initialised in the HTTP/2 protocol handler if the offending header was the very first one received or appeared in a a footer. This led to a NULL pointer dereference on initialised memory, crashing reliably the child process. Since such a triggering HTTP/2 request is easy to craft and submit, this can be exploited to DoS the server. This issue affected mod_http2 1.15.17 and Apache HTTP Server version 2.4.47 only. Apache HTTP Server 2.4.47 was never released.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | httpd | — | — |
| apache_software_foundation | apache_http_server | — | — |
| debian | apache2 | < apache2 2.4.46-5 (bookworm) | apache2 2.4.46-5 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_mod_http2_2.0.29-3_on_azure_linux_3.0 | — | — |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target HTTP/2-enabled Apache servers by sending a specially crafted HTTP/2 request where the very first header (or a header in a footer) violates server-configured size limitations, triggering a NULL pointer dereference and crashing the child process. ↗
- →The vulnerability is easy to trigger — any HTTP/2 request crafted to violate header size limits on the first header or a footer header is sufficient to crash the Apache child process, making automated scanning/exploitation trivial. ↗
- →Scope detection to Apache HTTP Server 2.4.47 with mod_http2 1.15.17 only; no other versions are affected. ↗
- →The vulnerable code was introduced via a specific upstream commit; use this to identify affected builds: https://github.com/icing/mod_h2/commit/1207f69bff3804c7920a57af7649d1eef8b645de ↗
- ·Only Apache HTTP Server 2.4.47 (which was never publicly released) with mod_http2 1.15.17 is affected; all other versions are not vulnerable. ↗
- ·Red Hat Enterprise Linux 6/7/8/9, JBoss Core Services, JBoss EAP 6, JBoss EWS 2, and Red Hat Software Collections httpd packages do not include the vulnerable code and are not affected. ↗
- ·The vulnerability only triggers when HTTP/2 is enabled (mod_http2 loaded); servers not using HTTP/2 are not affected. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_apache7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
NULL pointer dereference on specially crafted HTTP/2 request
vendor_msrc·2021-06-08·CVSS 7.5
CVE-2021-31618 [HIGH] CWE-476 NULL pointer dereference on specially crafted HTTP/2 request
NULL pointer dereference on specially crafted HTTP/2 request
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https:
Red Hat
httpd: NULL pointer dereference on specially crafted HTTP/2 request
vendor_redhat·2021-06-04·CVSS 7.5
CVE-2021-31618 [HIGH] CWE-476 httpd: NULL pointer dereference on specially crafted HTTP/2 request
httpd: NULL pointer dereference on specially crafted HTTP/2 request
Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used for the HTTP/1 protocol as well. On violation of these restrictions and HTTP response is sent to the client with a status code indicating why the request was rejected. This rejection response was not fully initialised in the HTTP/2 protocol handler if the offending header was the very first one received or appeared in a a footer. This led to a NULL pointer dereference on initialised memory, crashing reliably the child process. Since such a triggering HTTP/2 request is easy to craft and submit, this can be exploited to DoS the server. This issue affected mod_http2 1.
Debian
CVE-2021-31618: apache2 - Apache HTTP Server protocol handler for the HTTP/2 protocol checks received requ...
vendor_debian·2021·CVSS 7.5
CVE-2021-31618 [HIGH] CVE-2021-31618: apache2 - Apache HTTP Server protocol handler for the HTTP/2 protocol checks received requ...
Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used for the HTTP/1 protocol as well. On violation of these restrictions and HTTP response is sent to the client with a status code indicating why the request was rejected. This rejection response was not fully initialised in the HTTP/2 protocol handler if the offending header was the very first one received or appeared in a a footer. This led to a NULL pointer dereference on initialised memory, crashing reliably the child process. Since such a triggering HTTP/2 request is easy to craft and submit, this can be exploited to DoS the server. This issue affected mod_http2 1.15.17 and Apache HTTP Server version 2.4.47 only. Apache HTTP Server
Apache
Apache httpd: CVE-2021-31618
vendor_apache·CVSS 7.5
CVE-2021-31618 [HIGH] Apache httpd: CVE-2021-31618
Apache httpd: CVE-2021-31618
Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used for the HTTP/1 protocol as well. On violation of these restrictions and HTTP response is sent to the client with a status code indicating why the request was rejected. This rejection response was not fully initialised in the HTTP/2 protocol handler if the offending header was the very first one received or appeared in a a footer. This led to a NULL pointer dereference on initialised memory, crashing reliably the child process. Since such a triggering HTTP/2 request is easy to craft and submit, this can be exploited to DoS the server. This issue affected mod_http2 1.15.17 and Apache HTTP Server version 2.4
GHSA
GHSA-4jq3-qrx6-87cc: Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server
ghsa_unreviewed·2022-05-24
CVE-2021-31618 [HIGH] CWE-476 GHSA-4jq3-qrx6-87cc: Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server
Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used for the HTTP/1 protocol as well. On violation of these restrictions and HTTP response is sent to the client with a status code indicating why the request was rejected. This rejection response was not fully initialised in the HTTP/2 protocol handler if the offending header was the very first one received or appeared in a a footer. This led to a NULL pointer dereference on initialised memory, crashing reliably the child process. Since such a triggering HTTP/2 request is easy to craft and submit, this can be exploited to DoS the server. This issue affected mod_http2 1.15.17 and Apache HTTP Server version 2.4.47 only. Apache HTTP Server
OSV
CVE-2021-31618: Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server
osv·2021-06-15·CVSS 7.5
CVE-2021-31618 [HIGH] CVE-2021-31618: Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server
Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used for the HTTP/1 protocol as well. On violation of these restrictions and HTTP response is sent to the client with a status code indicating why the request was rejected. This rejection response was not fully initialised in the HTTP/2 protocol handler if the offending header was the very first one received or appeared in a a footer. This led to a NULL pointer dereference on initialised memory, crashing reliably the child process. Since such a triggering HTTP/2 request is easy to craft and submit, this can be exploited to DoS the server. This issue affected mod_http2 1.15.17 and Apache HTTP Server version 2.4.47 only. Apache HTTP Server
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://httpd.apache.org/security/vulnerabilities_24.htmlhttp://www.openwall.com/lists/oss-security/2021/06/10/9http://www.openwall.com/lists/oss-security/2024/03/13/2https://lists.apache.org/thread.html/r14b66ef0f4f569fd515a3f96cd4eb58bd9a8ff525cc326bb0359664f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r783b6558abf3305b17ea462bed4bd66d82866438999bf38cef6d11d1%40%3Ccvs.httpd.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/07/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2NKJ3ZA3FTSZ2QBBPKS6BYGAWYRABNQQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A73QJ4HPUMU26I6EULG6SCK67TUEXZYR/https://seclists.org/oss-sec/2021/q2/206https://security.gentoo.org/glsa/202107-38https://security.netapp.com/advisory/ntap-20210727-0008/https://www.debian.org/security/2021/dsa-4937https://www.oracle.com/security-alerts/cpuoct2021.htmlhttp://httpd.apache.org/security/vulnerabilities_24.htmlhttp://www.openwall.com/lists/oss-security/2021/06/10/9http://www.openwall.com/lists/oss-security/2024/03/13/2https://lists.apache.org/thread.html/r14b66ef0f4f569fd515a3f96cd4eb58bd9a8ff525cc326bb0359664f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r783b6558abf3305b17ea462bed4bd66d82866438999bf38cef6d11d1%40%3Ccvs.httpd.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/07/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2NKJ3ZA3FTSZ2QBBPKS6BYGAWYRABNQQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A73QJ4HPUMU26I6EULG6SCK67TUEXZYR/https://seclists.org/oss-sec/2021/q2/206https://security.gentoo.org/glsa/202107-38https://security.netapp.com/advisory/ntap-20210727-0008/https://www.debian.org/security/2021/dsa-4937https://www.oracle.com/security-alerts/cpuoct2021.html
2021-06-15
Published