CVE-2016-1546: Apache HTTP Server
Medium severity, CVSS 5.9. EPSS: 15.9% chance of exploitation in the next 30 days.
The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows.
Affected products
- Apache HTTP Server: version 2.4.17 only; version 2.4.18 only
Published 2016-07-06. Last modified 2026-06-17.