Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2009-1955

65
FAUCET Score

CVE-2009-1955 describes a denial-of-service vulnerability in the expat XML parser used by Apache APR-util, specifically affecting Apache HTTP Server's mod_dav and mod_dav_svn modules, as well as products from Apple, Oracle, and various Linux distributions. This flaw allows remote attackers to exhaust memory by sending crafted XML documents with deeply nested entity references, such as through a PROPFIND request. Rated with a CVSS score of 7.5 (HIGH), it is easily exploitable over the network with low attack complexity, leading to a high impact on availability. While not actively exploited in the wild or on the KEV catalog, public exploit code exists on ExploitDB, though it has garnered minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.3.7CPE matchmatch criteria
cpe:2.3:a:apache:apr-util:*:*:*:*:*:*:*:*
< 10.6.2CPE matchmatch criteria
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
9CPE matchmatch criteria
cpe:2.3:o:suse:linux_enterprise_server:9:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
6.06CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
52.99%
Probability of exploitation in next 30 days
EPSS Percentile
98.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
ExploitDB: EDB-8842 · Jun 1, 2009
This CVE's current EPSS score of 0.5299 is in the 98th percentile among its peer group of 51,455 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (25)

oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: JBEWS 1.0 for RHEL 4Fixed in: httpd22-0:2.2.10-23.1.ep5.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: ant-0:1.6.5-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: avalon-logkit-0:1.2-2jpp_4rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: axis-0:1.2.1-1jpp_3rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: classpathx-jaf-0:1.0-2jpp_6rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: classpathx-mail-0:1.1.1-2jpp_8rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: geronimo-specs-0:1.0-0.M4.1jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: jakarta-commons-modeler-0:2.0-3jpp_2rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: log4j-0:1.2.12-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: mx4j-1:3.0.1-1jpp_4rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: pcsc-lite-0:1.3.3-3.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-ca-0:7.3.0-20.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-java-tools-0:7.3.0-10.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-kra-0:7.3.0-14.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-manage-0:7.3.0-19.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-native-tools-0:7.3.0-6.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-ocsp-0:7.3.0-13.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-tks-0:7.3.0-13.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: tomcat5-0:5.5.23-0jpp_4rh.16
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: xerces-j2-0:2.7.1-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: xml-commons-0:1.3.02-2jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: httpd-0:2.0.46-73.ent
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: apr-util-0:0.9.4-22.el4_8.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: apr-util-0:1.2.7-7.el5_3.1
View patch

Vendor Advisories (1)

redhatCVE-2009-1955Moderate

apr-util billion laughs attack

Jun 1, 2009

References

lists.apple.com / archives/security-announce/2009/Nov/msg00000.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2010-05/msg00001.html
Mailing ListThird Party Advisory
marc.info
Mailing ListPatch
marc.info
Mailing List
secunia.com / advisories/34724
Broken LinkThird Party Advisory
secunia.com / advisories/35284
Broken LinkThird Party Advisory
secunia.com / advisories/35360
Broken LinkThird Party Advisory
secunia.com / advisories/35395
Broken LinkThird Party Advisory
secunia.com / advisories/35444
Broken LinkThird Party Advisory
secunia.com / advisories/35487
Broken LinkThird Party Advisory
secunia.com / advisories/35565
Broken LinkThird Party Advisory
secunia.com / advisories/35710
Broken LinkThird Party Advisory
secunia.com / advisories/35797
Broken LinkThird Party Advisory
secunia.com / advisories/35843
Broken LinkThird Party Advisory
secunia.com / advisories/36473
Broken LinkThird Party Advisory
secunia.com / advisories/37221
Broken LinkThird Party Advisory
security.gentoo.org / glsa/glsa-200907-03.xml
Third Party Advisory
slackware.com / security/viewer.php
Broken LinkThird Party Advisory
lists.apache.org / thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E
Mailing ListPatch
lists.apache.org / thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E
Mailing ListPatch
lists.apache.org / thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E
Mailing ListPatch
lists.apache.org / thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E
Mailing ListPatch
lists.apache.org / thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E
Mailing ListPatch
lists.apache.org / thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E
Mailing ListPatch
lists.apache.org / thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E
Mailing ListPatch
lists.apache.org / thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E
Mailing ListPatch
lists.apache.org / thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E
Mailing ListPatch
lists.apache.org / thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E
Mailing ListPatch
lists.apache.org / thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E
Mailing ListPatch
lists.apache.org / thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E
Mailing ListPatch
lists.apache.org / thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
Mailing ListPatch
lists.apache.org / thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E
Mailing ListPatch
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10270
Broken LinkThird Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12473
Broken LinkThird Party Advisory
support.apple.com / kb/HT3937
Broken Link
svn.apache.org / viewvc
Patch
exploit-db.com / exploits/8842
ExploitVDB Entry
redhat.com / archives/fedora-package-announce/2009-June/msg01173.html
Mailing List
redhat.com / archives/fedora-package-announce/2009-June/msg01201.html
Mailing List
redhat.com / archives/fedora-package-announce/2009-June/msg01228.html
Mailing List
wiki.rpath.com / Advisories:rPSA-2009-0123
Broken Link
www-01.ibm.com / support/docview.wss
Broken Link
www-01.ibm.com / support/docview.wss
Broken LinkThird Party Advisory
www-01.ibm.com / support/docview.wss
Broken LinkThird Party Advisory
www-01.ibm.com / support/docview.wss
Broken LinkThird Party Advisory
apache.org / dist/apr/CHANGES-APR-UTIL-1.3
Broken Link
debian.org / security/2009/dsa-1812
Mailing ListThird Party Advisory
mandriva.com / security/advisories
Broken LinkThird Party Advisory
mandriva.com / security/advisories
Broken LinkThird Party Advisory
openwall.com / lists/oss-security/2009/06/03/4
Mailing List
oracle.com / technetwork/topics/security/cpuapr2013-1899555.html
PatchThird Party Advisory
redhat.com / support/errata/RHSA-2009-1107.html
Broken LinkThird Party Advisory
redhat.com / support/errata/RHSA-2009-1108.html
Broken LinkThird Party Advisory
securityfocus.com / archive/1/506053/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / bid/35253
Broken LinkThird Party AdvisoryVDB Entry
ubuntu.com / usn/usn-786-1
Third Party Advisory
ubuntu.com / usn/usn-787-1
Third Party Advisory
vupen.com / english/advisories/2009/1907
Broken LinkThird Party Advisory
vupen.com / english/advisories/2009/3184
Broken LinkThird Party Advisory
vupen.com / english/advisories/2010/1107
Broken LinkThird Party Advisory