Unrated severityNVD Advisory· Published Jul 10, 2025· Updated Nov 4, 2025
Apache HTTP Server: mod_proxy_http2 denial of service
CVE-2025-49630
Description
In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2.
Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".
Affected products
2- Range: >=2.4.26 <=2.4.63
- Apache Software Foundation/Apache HTTP Serverv5Range: 2.4.26
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- httpd.apache.org/security/vulnerabilities_24.htmlmitrevendor-advisory
News mentions
0No linked articles in our index yet.