cbcvebase.
CVE-2021-31618
published 2021-06-15

CVE-2021-31618: Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used…

PriorityP355high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
51.21%
98.8th percentile
Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used for the HTTP/1 protocol as well. On violation of these restrictions and HTTP response is sent to the client with a status code indicating why the request was rejected. This rejection response was not fully initialised in the HTTP/2 protocol handler if the offending header was the very first one received or appeared in a a footer. This led to a NULL pointer dereference on initialised memory, crashing reliably the child process. Since such a triggering HTTP/2 request is easy to craft and submit, this can be exploited to DoS the server. This issue affected mod_http2 1.15.17 and Apache HTTP Server version 2.4.47 only. Apache HTTP Server 2.4.47 was never released.

Affected

15 ranges
VendorProductVersion rangeFixed in
apachehttp_server
apachehttp_server
apachehttpd
apache_software_foundationapache_http_server
debianapache2< apache2 2.4.46-5 (bookworm)apache2 2.4.46-5 (bookworm)
debiandebian_linux
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
msrcazl3_mod_http2_2.0.29-3_on_azure_linux_3.0
oracleenterprise_manager_ops_center
oracleinstantis_enterprisetrack
oracleinstantis_enterprisetrack
oracleinstantis_enterprisetrack
oraclezfs_storage_appliance_kit

Detection & IOCsextracted from sources · hover to see the quote

  • Target HTTP/2-enabled Apache servers by sending a specially crafted HTTP/2 request where the very first header (or a header in a footer) violates server-configured size limitations, triggering a NULL pointer dereference and crashing the child process.
  • The vulnerability is easy to trigger — any HTTP/2 request crafted to violate header size limits on the first header or a footer header is sufficient to crash the Apache child process, making automated scanning/exploitation trivial.
  • Scope detection to Apache HTTP Server 2.4.47 with mod_http2 1.15.17 only; no other versions are affected.
  • The vulnerable code was introduced via a specific upstream commit; use this to identify affected builds: https://github.com/icing/mod_h2/commit/1207f69bff3804c7920a57af7649d1eef8b645de
  • ·Only Apache HTTP Server 2.4.47 (which was never publicly released) with mod_http2 1.15.17 is affected; all other versions are not vulnerable.
  • ·Red Hat Enterprise Linux 6/7/8/9, JBoss Core Services, JBoss EAP 6, JBoss EWS 2, and Red Hat Software Collections httpd packages do not include the vulnerable code and are not affected.
  • ·The vulnerability only triggers when HTTP/2 is enabled (mod_http2 loaded); servers not using HTTP/2 are not affected.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_apache7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.