CVE-2019-0197: Apache HTTP Server
Medium severity, CVSS 4.2. EPSS: 8.6% chance of exploitation in the next 30 days.
A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection could lead to a misconfiguration and crash. Server that never enabled the h2 protocol or that only enabled it for https: and did not set "H2Upgrade on" are unaffected by this issue.
Affected products
- Apache HTTP Server: from 2.4.34, up to and including 2.4.38
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only
- Fedoraproject Fedora: version 30 only
- Opensuse Leap: version 15.0 only; version 42.3 only
- Oracle Communications Session Report Manager: version 8.0.0 only; version 8.1.0 only; version 8.1.1 only; version 8.2.0 only
- Oracle Communications Session Route Manager: version 8.0.0 only; version 8.1.0 only; version 8.1.1 only; version 8.2.0 only
- Oracle Enterprise Manager Ops Center: version 12.3.3 only; version 12.4.0 only
- Oracle HTTP Server: version 12.2.1.3.0 only
- Oracle Instantis Enterprisetrack: version 17.1 only; version 17.2 only; version 17.3 only
- Oracle Retail Xstore Point Of Service: version 7.0 only; version 7.1 only
- Red Hat JBoss Core Services: version 1.0 only
Published 2019-06-11. Last modified 2026-06-17.