Apache HTTP Server: mod_proxy_http2 denial of service
Vulnerability Description
In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-49630
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Anthony CORSIEZ
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →