CVE-2016-8734: Apache Subversion

Medium severity, CVSS 6.5. EPSS: 6.4% chance of exploitation in the next 30 days.

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.

Affected products

  • Apache Subversion: version 1.4.0 only; version 1.4.1 only; version 1.4.2 only; version 1.4.3 only; version 1.4.4 only; version 1.4.5 only; …
  • Debian Debian Linux: version 8.0 only; version 9.0 only

Published 2017-10-16. Last modified 2026-06-17.