CVE-2025-53020
published 2025-07-10CVE-2025-53020: Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.41%
90.3th percentile
Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63.
Users are recommended to upgrade to version 2.4.64, which fixes the issue.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.4.17 < 2.4.64 | 2.4.64 |
| apache | httpd | — | — |
| apache_software_foundation | apache_http_server | 2.4.17 – 2.4.63 | — |
| debian | apache2 | < apache2 2.4.65-1~deb12u1 (bookworm) | apache2 2.4.65-1~deb12u1 (bookworm) |
| msrc | azl3_httpd_2.4.62-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_httpd_2.4.64-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_httpd_2.4.62-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_httpd_2.4.64-1_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_apache7.5
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
apache2 vulnerabilities
osv·2025-08-19·CVSS 7.5
CVE-2025-49630 [HIGH] apache2 vulnerabilities
apache2 vulnerabilities
USN-7639-1 fixed several vulnerabilities in Apache. This update
provides the corresponding update for Ubuntu 16.04 LTS, Ubuntu
18.04 LTS, Ubuntu 20.04 LTS, and addressed a regression
fix (LP: #2119395). CVE-2025-49630 and CVE-2025-53020 only
affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that the Apache HTTP Server incorrectly handled
certain Content-Type response headers. A remote attacker could
possibly use this issue to perform HTTP response splitting attacks.
(CVE-2024-42516)
xiaojunjie discovered that the Apache HTTP Server mod_proxy module
incorrectly handled certain requests. A remote attacker could
possibly use this issue to send outbound proxy requests to an
arbitrary URL. (CVE-2024-43204)
John Runyon disco
OSV
apache2 vulnerabilities
osv·2025-07-16·CVSS 7.5
CVE-2024-42516 [HIGH] apache2 vulnerabilities
apache2 vulnerabilities
It was discovered that the Apache HTTP Server incorrectly handled certain
Content-Type response headers. A remote attacker could possibly use this
issue to perform HTTP response splitting attacks. (CVE-2024-42516)
xiaojunjie discovered that the Apache HTTP Server mod_proxy module
incorrectly handled certain requests. A remote attacker could possibly use
this issue to send outbound proxy requests to an arbitrary URL.
(CVE-2024-43204)
John Runyon discovered that the Apache HTTP Server mod_ssl module
incorrectly escaped certain data. A remote attacker could possibly use this
issue to insert escape characters into log files. (CVE-2024-47252)
Sven Hebrok, Felix Cramer, Tim Storm, Maximilian Radoy, and Juraj
Somorovsky discovered that the Apache HTTP Server mod_ssl mo
OSV
CVE-2025-53020: Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server
osv·2025-07-10·CVSS 7.5
CVE-2025-53020 [HIGH] CVE-2025-53020: Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server
Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.
OSV
CVE-2025-53020: Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server
osv·2025-07-10·CVSS 7.5
CVE-2025-53020 [HIGH] CVE-2025-53020: Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server
Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63.
Users are recommended to upgrade to version 2.4.64, which fixes the issue.
GHSA
GHSA-c2vf-6g7v-8m6c: Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server
ghsa_unreviewed·2025-07-10
CVE-2025-53020 [HIGH] CWE-401 GHSA-c2vf-6g7v-8m6c: Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server
Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63.
Users are recommended to upgrade to version 2.4.64, which fixes the issue.
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2025-08-19·CVSS 7.5
CVE-2024-43204 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
USN-7639-1 fixed several vulnerabilities in Apache. This update
provides the corresponding update for Ubuntu 16.04 LTS, Ubuntu
18.04 LTS, Ubuntu 20.04 LTS, and addressed a regression
fix (LP: #2119395). CVE-2025-49630 and CVE-2025-53020 only
affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that the Apache HTTP Server incorrectly handled
certain Content-Type response headers. A remote attacker could
possibly use this issue to perform HTTP response splitting attacks.
(CVE-2024-42516)
xiaojunjie discovered that the Apache HTTP Server mod_proxy module
incorrectly handled certain requests. A remote attacker could
possibly use this issue to
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2025-07-16·CVSS 7.5
CVE-2025-49812 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
It was discovered that the Apache HTTP Server incorrectly handled certain
Content-Type response headers. A remote attacker could possibly use this
issue to perform HTTP response splitting attacks. (CVE-2024-42516)
xiaojunjie discovered that the Apache HTTP Server mod_proxy module
incorrectly handled certain requests. A remote attacker could possibly use
this issue to send outbound proxy requests to an arbitrary URL.
(CVE-2024-43204)
John Runyon discovered that the Apache HTTP Server mod_ssl module
incorrectly escaped certain data. A remote attacker could possibly use this
issue to insert escape characters into log files. (CVE-2024-47252)
Sven Hebrok, Felix Cramer, Tim Storm, Ma
Red Hat
httpd: Apache HTTP Server: HTTP/2 DoS by Memory Increase
vendor_redhat·2025-07-10·CVSS 7.5
CVE-2025-53020 [HIGH] CWE-401 httpd: Apache HTTP Server: HTTP/2 DoS by Memory Increase
httpd: Apache HTTP Server: HTTP/2 DoS by Memory Increase
Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63.
Users are recommended to upgrade to version 2.4.64, which fixes the issue.
A flaw was found in Apache HTTP Server. This late release of memory after effective lifetime vulnerability allows a remote, unauthenticated attacker to cause a denial of service (DoS). The vulnerability can lead to resource exhaustion, making the server unavailable to legitimate users.
Mitigation: The attack surface can be reduced by disabling HTTP/2 support in Apache.
Follow the guidance in Red Hat KCS article to:
- Remove h2 and h2c from the Protocols directive
- Disable mod_http2 and mod_proxy_http2 modules
Microsoft
Apache HTTP Server: HTTP/2 DoS by Memory Increase
vendor_msrc·2025-07-08·CVSS 7.5
CVE-2025-53020 [HIGH] CWE-401 Apache HTTP Server: HTTP/2 DoS by Memory Increase
Apache HTTP Server: HTTP/2 DoS by Memory Increase
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.mic
Debian
CVE-2025-53020: apache2 - Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Ser...
vendor_debian·2025·CVSS 7.5
CVE-2025-53020 [HIGH] CVE-2025-53020: apache2 - Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Ser...
Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.
Scope: local
bookworm: resolved (fixed in 2.4.65-1~deb12u1)
bullseye: resolved (fixed in 2.4.65-1~deb11u1)
forky: resolved (fixed in 2.4.64-1)
sid: resolved (fixed in 2.4.64-1)
trixie: resolved (fixed in 2.4.64-1)
Apache
Apache httpd: CVE-2025-53020
vendor_apache·CVSS 7.5
CVE-2025-53020 Apache httpd: CVE-2025-53020
Apache httpd: CVE-2025-53020
Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue. Acknowledgements: finder: Gal Bar Nahum Reported to security team 2025-06-18 fix developed 2025-06-19 Update 2.4.64 released 2025-07-10 Affects 2.4.17 through 2.4.63
Severity: moderate
Affected versions: 2.4.64,
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-53020 httpd: Apache HTTP Server: HTTP/2 DoS by Memory Increase
bugzilla·2025-07-10·CVSS 7.5
CVE-2025-53020 [HIGH] CVE-2025-53020 httpd: Apache HTTP Server: HTTP/2 DoS by Memory Increase
CVE-2025-53020 httpd: Apache HTTP Server: HTTP/2 DoS by Memory Increase
Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63.
Users are recommended to upgrade to version 2.4.64, which fixes the issue.
Hackernews
New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
blogs_hackernews·2026-06-03·CVSS 7.5
CVE-2016-6581 [HIGH] New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora.
The vulnerability has been codenamed HTTP/2 Bomb by Calif.
"The vulnerable behavior exists in each server's default HTTP/2 configuration," the company said, adding it was discovered by OpenAI Codex by chaining together two known techniques: a compression bomb and a Slowloris -style hold.
"The bomb targets HPACK, HTTP/2's header compression scheme: one
2025-07-10
Published