CVE-2020-9490 affects Apache HTTP Server versions 2.4.20 to 2.4.43, where a specially crafted Cache-Digest header in an HTTP/2 request can cause a server crash when attempting to HTTP/2 PUSH a resource. This vulnerability has a CVSS score of 7.5 (High), indicating it can be exploited remotely with low complexity to cause a denial of service. While no public exploit code or active exploitation has been confirmed, its high FAUCET Risk Score of 98/100 and above-average community discussion suggest it warrants attention. Mitigation for unpatched servers involves configuring the HTTP/2 feature with "H2Push off".
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.4.20, < 2.4.46CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
>= 8.2.0, <= 8.2.2CPE matchmatch criteria | cpe:2.3:a:oracle:communications_element_manager:*:*:*:*:*:*:*:* | ||
>= 8.2.0, <= 8.2.2CPE matchmatch criteria | cpe:2.3:a:oracle:communications_session_report_manager:*:*:*:*:*:*:*:* | ||
>= 8.2.0, <= 8.2.2CPE matchmatch criteria | cpe:2.3:a:oracle:communications_session_route_manager:*:*:*:*:*:*:*:* | ||
12.4.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.
Aug 11, 2020httpd: Push diary crash on specifically crafted HTTP/2 header
Aug 7, 2020Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project