CVE-2016-4979 is a bypass vulnerability affecting Apache HTTP Server versions 2.4.18 through 2.4.20 when mod_http2 and mod_ssl are enabled. Attackers can bypass access restrictions by sending multiple requests over a single connection and aborting a renegotiation, circumventing the "SSLVerifyClient require" directive. This vulnerability has a high CVSS score of 7.5, indicating a network-based attack with low complexity and high impact on integrity. While its EPSS and FAUCET scores suggest elevated risk, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the KEV catalog. Community discussion and media coverage are minimal, with the single article incorrectly linking it to a different CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4.18CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.18:*:*:*:*:*:*:* | ||
2.4.19CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.19:*:*:*:*:*:*:* | ||
2.4.20CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.20:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: X509 client certificate authentication bypass using HTTP/2
Jul 5, 2016Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project