CVE-2018-11763: Apache HTTP Server

Medium severity, CVSS 5.9. EPSS: 50.8% chance of exploitation in the next 30 days.

In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.

Affected products

  • Apache HTTP Server: from 2.4.17, up to and including 2.4.34
  • Canonical Ubuntu Linux: version 18.04 only
  • Netapp Storage Automation Store: affected versions not specified
  • Oracle Enterprise Manager Ops Center: version 12.3.3 only
  • Oracle Hospitality Guest Access: version 4.2.0 only; version 4.2.1 only
  • Oracle Instantis Enterprisetrack: version 17.1 only; version 17.2 only; version 17.3 only
  • Oracle Retail Xstore Point Of Service: version 7.0 only; version 7.1 only
  • Oracle Secure Global Desktop: version 5.4 only
  • Red Hat Enterprise Linux: version 6.0 only; version 7.0 only; version 7.4 only; version 7.5 only; version 7.6 only

Published 2018-09-25. Last modified 2026-06-17.