high CVSS 7.5

CVE-2024-27316·Apache vulnerability

HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.

Severity
high
Software
Apache
Fixed in
2.4.59
Published
2024-04-04

Affected versions

From: 2.4.17

Until: 2.4.59

Fixed in: 2.4.59

How to fix this CVE

Update Apache HTTP Server to version 2.4.59 or later to patch the HTTP/2 header buffering vulnerability. This fix prevents memory exhaustion attacks that exploit improper handling of oversized incoming headers. Prioritize this update for production systems exposed to untrusted network traffic, as the vulnerability requires no authentication or user interaction.

sudo dnf update httpd

Defensia detects this vulnerability

What an exploitation attempt looks like

Sample log line indicative of exploitation attempts:

Repeated or malformed HTTP/2 HEADERS frames with abnormally large header block sizes (exceeding LimitRequestFields or LimitRequestFieldSize thresholds) sent from a single client IP without completing the request lifecycle. Log pattern: 'h2.*headers.*exceeding' or abnormal increases in child process memory usage correlated with HTTP/2 connections.

WAF mitigation (if patching is not yet possible)

Add this rule to your WAF to block exploitation attempts while you schedule the patch.

Implement HTTP/2 header size limits at the WAF level by rejecting HEADERS frames or requests with cumulative header size exceeding a reasonable threshold (e.g., 16KB total). Set rate limits on header-heavy requests per IP to mitigate header flooding attempts before they reach the Apache backend.

How to check if you are affected

  1. Run 'apache2ctl -v' or 'httpd -v' to check the currently installed Apache version and compare it against 2.4.59.
  2. Verify HTTP/2 support is enabled by checking if mod_http2 is loaded: grep -i 'mod_http2' /etc/apache2/mods-enabled/* or httpd -M | grep http2.
  3. Search Apache access and error logs for repeated or sustained HTTP/2 HEADERS frame activity without corresponding request completion: grep -i 'h2' /var/log/apache2/error.log | tail -100.
  4. After patching, re-run 'apache2ctl -v' or 'httpd -v' to confirm the version is 2.4.59 or later, then restart Apache with 'sudo systemctl restart apache2' or 'sudo systemctl restart httpd' and verify normal operation.

FAQ

What is CVE-2024-27316?

CVE-2024-27316 is a denial-of-service vulnerability in Apache HTTP Server's HTTP/2 implementation where the server buffers excessively large incoming headers while attempting to generate a 413 response. An attacker can exploit this by continuously sending oversized headers, causing unbounded memory consumption and server crash.

Is CVE-2024-27316 being actively exploited?

No, according to CISA's Known Exploited Vulnerabilities (KEV) catalog, CVE-2024-27316 is not currently being exploited in the wild, and no public exploit code has been released.

What versions of Apache are affected by CVE-2024-27316?

Apache HTTP Server versions 2.4.17 through 2.4.58 are vulnerable. Version 2.4.59 and all subsequent releases include the fix.

How do I check if my server is vulnerable to CVE-2024-27316?

Execute 'apache2ctl -v' or 'httpd -v' and check if the version falls between 2.4.17 and 2.4.58. If HTTP/2 is enabled (verify with 'httpd -M | grep http2'), your server is vulnerable until you update to 2.4.59 or later.

Does Defensia detect CVE-2024-27316?

Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2024-27316 will appear in your dashboard with remediation steps.

Related Apache CVEs

CVE-2024-38474CVSS 9.8Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.
CVE-2024-38476CVSS 9.8Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
CVE-2024-38475CVSS 9.1Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected.  Some unsafe RewiteRules will be broken by this change and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained.
CVE-2025-23048CVSS 9.1In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected when mod_ssl is configured for multiple virtual hosts, with each restricted to a different set of trusted client certificates (for example with a different SSLCACertificateFile/Path setting). In such a case, a client trusted to access one virtual host may be able to access another virtual host, if SSLStrictSNIVHostCheck is not enabled in either virtual host.
CVE-2025-58098CVSS 8.3Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

References

Track CVEs across your fleet automatically

Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-27316. Free for 1 server.

Get started free