CVE-2018-1333: Apache HTTP Server

High severity, CVSS 7.5. EPSS: 17.1% chance of exploitation in the next 30 days.

By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).

Affected products

  • Apache HTTP Server: from 2.4.18, up to and including 2.4.30; version 2.4.33 only
  • Canonical Ubuntu Linux: version 18.04 only
  • Netapp Cloud Backup: affected versions not specified
  • Netapp Storage Automation Store: affected versions not specified
  • Red Hat JBoss Core Services: version 1.0 only

Published 2018-06-18. Last modified 2026-06-17.