CVE-2022-30522 is a Denial of Service (DoS) vulnerability affecting Apache HTTP Server 2.4.53 when configured with mod_sed to process large inputs, leading to excessive memory allocation and server aborts. This vulnerability has a CVSS score of 7.5 (High), indicating a network-based attack with low complexity and high availability impact, though no confidentiality or integrity impact. While the FAUCET Risk Score is high at 91/100 and there's some community discussion, there is currently no evidence of active exploitation, nor are there publicly available exploit tools like Metasploit or Nuclei modules.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4.53CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.53:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: mod_sed: DoS vulnerability
Jun 8, 2022Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project