CVE-2016-1546 describes a denial-of-service vulnerability affecting Apache HTTP Server versions 2.4.17 and 2.4.18 when mod_http2 is enabled. Attackers can exploit this by manipulating flow-control windows, leading to a stream-processing outage. This medium-severity flaw (CVSS 5.9) has a high impact on availability and is remotely exploitable with high attack complexity. While there is no known exploit code or active exploitation, the vulnerability has garnered significant community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4.17CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.17:*:*:*:*:*:*:* | ||
2.4.18CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.18:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: mod_http2 denial-of-service by thread starvation
Apr 11, 2016Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project