Home

Description

In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".

PUBLISHED Reserved 2025-06-08 | Published 2025-07-10 | Updated 2025-11-04 | Assigner apache

Problem types

CWE-617 Reachable Assertion

Product status

Default status
unaffected

2.4.26 (semver)
affected

Timeline

2025-06-04:Report received

Credits

Anthony CORSIEZ finder

References

lists.debian.org/debian-lts-announce/2025/08/msg00009.html

www.openwall.com/lists/oss-security/2025/07/10/2

www.openwall.com/lists/oss-security/2025/07/10/7

httpd.apache.org/security/vulnerabilities_24.html vendor-advisory

cve.org (CVE-2025-49630)

nvd.nist.gov (CVE-2025-49630)

Download JSON