CVE-2016-8612: Apache HTTP Server

Medium severity, CVSS 4.3. EPSS: 4.4% chance of exploitation in the next 30 days.

Apache HTTP Server mod_cluster before version httpd 2.4.23 is vulnerable to an Improper Input Validation in the protocol parsing logic in the load balancer resulting in a Segmentation Fault in the serving httpd process.

Affected products

  • Apache HTTP Server: before 2.4.23 (fixed in 2.4.23)
  • Netapp Storage Automation Store: affected versions not specified
  • Red Hat Enterprise Linux: version 6.0 only; version 7.0 only

Published 2018-03-09. Last modified 2026-06-17.