CVE-2025-49630: Apache HTTP Server
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".
Affected products
- Apache HTTP Server: from 2.4.26, before 2.4.64 (fixed in 2.4.64)
Published 2025-07-10. Last modified 2026-06-17.