cbcvebase.
CVE-2022-22721
published 2022-03-14

CVE-2022-22721: If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out…

PriorityP264critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
41.86%
98.5th percentile
If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

Affected

21 ranges
VendorProductVersion rangeFixed in
apachehttp_server<= 2.4.52
apache_software_foundationapache_http_serverApache HTTP Server 2.4 – 2.4.52
applemac_os_x
applemac_os_x>= 10.15 < 10.15.710.15.7
applemacos>= 11.0 < 11.6.611.6.6
applemacos>= 12.0 < 12.412.4
applemacos_big_sur
applemacos_monterey
applesecurity_update_2022-004_catalina
debianapache2< apache2 2.4.53-1 (bookworm)apache2 2.4.53-1 (bookworm)
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_httpd_2.4.53-1_on_cbl_mariner_2.0
msrccm1_httpd_2.4.53-1_on_cbl_mariner_1.0
oracleenterprise_manager_ops_center
oraclehttp_server
oraclehttp_server
oraclezfs_storage_appliance_kit
paloaltopan-os

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is only exploitable on 32-bit Apache HTTP Server builds when LimitXMLRequestBody is set to a value larger than 350MB; monitor configurations for oversized LimitXMLRequestBody values on 32-bit systems
  • Detect exploitation attempts by monitoring for abnormally large XML request bodies (>350MB) sent to Apache HTTP Server endpoints, which would trigger the integer overflow on 32-bit systems
  • This issue is known to only affect 32-bit httpd builds; scope detection and patching efforts accordingly
  • ·Default LimitXMLRequestBody of 1MB is NOT vulnerable; only configurations explicitly set above 350MB on 32-bit systems are at risk
  • ·Setting LimitXMLRequestBody to 0 is not a safe mitigation — it applies a hard limit that may cause system out-of-memory conditions; set it to a value explicitly below 350MB instead
  • ·Affected versions include Apache HTTP Server 2.4.52 and earlier; ensure patched versions are deployed

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv9.1CRITICAL
vendor_oracle9.8CRITICAL
vendor_debian9.1CRITICAL
vendor_msrc9.1CRITICAL
vendor_redhat9.1CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.