CVE-2024-27316: Apache HTTP Server

High severity, CVSS 7.5. EPSS: 91.3% chance of exploitation in the next 30 days.

HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.

Affected products

  • Apache HTTP Server: from 2.4.17, before 2.4.59 (fixed in 2.4.59)
  • Fedoraproject Fedora: version 38 only; version 39 only; version 40 only
  • Netapp Ontap: version 9 only

Published 2024-04-04. Last modified 2026-06-17.