CVE-2022-28615: Apache HTTP Server

Critical severity, CVSS 9.1. EPSS: 6.3% chance of exploitation in the next 30 days.

Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua scripts that use ap_strcmp_match() may hypothetically be affected.

Affected products

  • Apache HTTP Server: before 2.4.54 (fixed in 2.4.54)
  • Fedoraproject Fedora: version 35 only; version 36 only
  • Netapp Clustered Data Ontap: affected versions not specified

Published 2022-06-09. Last modified 2026-06-17.