CVE-2014-0226: Apache HTTP Server

Medium severity, CVSS 6.8. EPSS: 85.7% chance of exploitation in the next 30 days.

Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a crafted request that triggers improper scoreboard handling within the status_handler function in modules/generators/mod_status.c and the lua_ap_scoreboard_worker function in modules/lua/lua_request.c.

Affected products

  • Apache HTTP Server: from 2.2.0, before 2.2.29 (fixed in 2.2.29); from 2.4.1, before 2.4.10 (fixed in 2.4.10)
  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • Oracle Enterprise Manager Ops Center: version 11.1.3 only; version 12.1.4 only
  • Oracle HTTP Server: version 10.1.3.5.0 only; version 11.1.1.7.0 only; version 12.1.2.0 only; version 12.1.3.0 only
  • Oracle Secure Global Desktop: version 4.63 only; version 4.71 only; version 5.0 only; version 5.1 only
  • Red Hat JBoss Enterprise Application Platform: version 6.0.0 only; version 6.4.0 only

Published 2014-07-20. Last modified 2026-06-17.