CVE-2016-2161 describes a denial-of-service vulnerability in Apache HTTP Server versions 2.4.0 to 2.4.23, where malicious input to mod_auth_digest can cause the server to crash repeatedly. This vulnerability is rated as High severity (CVSS 7.5), indicating it can be exploited remotely with low complexity to achieve a complete loss of availability. While there is no known active exploitation or public exploit code, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4.0CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.0:*:*:*:*:*:*:* | ||
2.4.1CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.1:*:*:*:*:*:*:* | ||
2.4.2CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.2:*:*:*:*:*:*:* | ||
2.4.3CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.3:*:*:*:*:*:*:* | ||
2.4.6CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: DoS vulnerability in mod_auth_digest
Dec 20, 2016Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project