CVE-2025-49630: Apache HTTP Server

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".

Affected products

  • Apache HTTP Server: from 2.4.26, before 2.4.64 (fixed in 2.4.64)

Published 2025-07-10. Last modified 2026-06-17.