CVE-2017-9789: Apache HTTP Server

High severity, CVSS 7.5. EPSS: 9.6% chance of exploitation in the next 30 days.

When under stress, closing many connections, the HTTP/2 handling code in Apache httpd 2.4.26 would sometimes access memory after it has been freed, resulting in potentially erratic behaviour.

Affected products

  • Apache HTTP Server: version 2.4.26 only

Published 2017-07-13. Last modified 2026-06-17.