CVE-2015-0228 describes a denial-of-service vulnerability in the mod_lua module of Apache HTTP Server versions through 2.4.12, also affecting products from Apple, Canonical, and OpenSUSE. An unauthenticated remote attacker can crash a child process by sending a crafted WebSocket Ping frame after a Lua script has called the wsupgrade function. With a CVSS score of 5.0, this vulnerability is of medium severity, requiring low attack complexity and resulting in partial availability impact. There is no evidence of active exploitation, nor are there publicly available exploit modules or proof-of-concept code. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.4.12CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
10.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:lts:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
14.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: Possible mod_lua crash due to websocket bug
Mar 10, 2015Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project