CVE-2025-49630

Published Jul 10, 2025

Last updated 3 days ago

Overview

Description
In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".
Source
security@apache.org
NVD status
Awaiting Analysis

Weaknesses

security@apache.org
CWE-617

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.