CVE-2014-0118: Apache HTTP Server

Medium severity, CVSS 4.3. EPSS: 37.2% chance of exploitation in the next 30 days.

The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses to a much larger size.

Affected products

  • Apache HTTP Server: from 2.2.0, before 2.2.29 (fixed in 2.2.29); from 2.4.1, before 2.4.10 (fixed in 2.4.10)
  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • Red Hat JBoss Enterprise Application Platform: version 6.0.0 only; version 6.4.0 only

Published 2014-07-20. Last modified 2026-06-17.