CVE-2018-1302: Apache HTTP Server
Medium severity, CVSS 5.9. EPSS: 12.9% chance of exploitation in the next 30 days.
When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard to trigger in usual configurations, the reporter and the team could not reproduce it outside debug builds, so it is classified as low risk.
Affected products
- Apache HTTP Server: up to and including 2.4.29
- Canonical Ubuntu Linux: version 18.04 only
- Netapp Clustered Data Ontap: affected versions not specified
- Netapp Santricity Cloud Connector: affected versions not specified
- Netapp Storage Automation Store: affected versions not specified
- Netapp Storagegrid: affected versions not specified
Published 2018-03-26. Last modified 2026-06-17.