CVE-2014-0231: Apache HTTP Server

Medium severity, CVSS 5.0. EPSS: 43.8% chance of exploitation in the next 30 days.

The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor.

Affected products

  • Apache HTTP Server: from 2.2.0, before 2.2.29 (fixed in 2.2.29); from 2.4.0, before 2.4.10 (fixed in 2.4.10)

Published 2014-07-20. Last modified 2026-06-17.