CVE-2018-1303: Apache HTTP Server
High severity, CVSS 7.5. EPSS: 69.8% chance of exploitation in the next 30 days.
A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared memory. It could be used as a Denial of Service attack against users of mod_cache_socache. The vulnerability is considered as low risk since mod_cache_socache is not widely used, mod_cache_disk is not concerned by this vulnerability.
Affected products
- Apache HTTP Server: up to and including 2.4.29
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 17.10 only; version 18.04 only
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Netapp Clustered Data Ontap: affected versions not specified
- Netapp Santricity Cloud Connector: affected versions not specified
- Netapp Storage Automation Store: affected versions not specified
- Netapp Storagegrid: affected versions not specified
Published 2018-03-26. Last modified 2026-06-17.