Description

In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".

INFO

Published Date :

2025-07-10T16:57:40.117Z

Last Modified :

2025-11-04T21:11:13.455Z

Source :

apache
AFFECTED PRODUCTS

The following products are affected by CVE-2025-49630 vulnerability.

Vendors Products
Apache
  • Apache Http Server
  • Http Server

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact