In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".
History

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00018}


Thu, 10 Jul 2025 17:15:00 +0000

Type Values Removed Values Added
Description In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".
Title Apache HTTP Server: mod_proxy_http2 denial of service
Weaknesses CWE-617
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2025-07-10T16:57:40.117Z

Updated: 2025-07-10T16:57:40.117Z

Reserved: 2025-06-08T19:44:51.747Z

Link: CVE-2025-49630

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-07-10T17:15:48.050

Modified: 2025-07-10T17:15:48.050

Link: CVE-2025-49630

cve-icon Redhat

No data.