CVE-2006-20001 describes a heap memory corruption vulnerability in Apache HTTP Server versions 2.4.54 and earlier. A specially crafted "If:" request header can lead to a memory read or a single zero-byte write beyond the header's value, potentially causing the server process to crash. This vulnerability carries a CVSS score of 7.5 (High), indicating a network-based attack with low complexity and high availability impact. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit or ExploitDB, the CVE has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.4.55CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
>= 2.4, <= 2.4.54CPE match | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: mod_dav: out-of-bounds read/write of zero byte
Jan 17, 2023Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project