CVE-2022-28615: Apache HTTP Server
Critical severity, CVSS 9.1. EPSS: 6.3% chance of exploitation in the next 30 days.
Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua scripts that use ap_strcmp_match() may hypothetically be affected.
Affected products
- Apache HTTP Server: before 2.4.54 (fixed in 2.4.54)
- Fedoraproject Fedora: version 35 only; version 36 only
- Netapp Clustered Data Ontap: affected versions not specified
Published 2022-06-09. Last modified 2026-06-17.