CVE-2016-8740 describes a denial-of-service vulnerability in the mod_http2 module of Apache HTTP Server versions 2.4.17 through 2.4.23. This flaw allows remote attackers to exhaust server memory by sending crafted HTTP/2 CONTINUATION frames when h2 or h2c protocols are enabled. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network with low attack complexity, leading to a high impact on availability. While not listed in CISA's KEV catalog, an exploit is publicly available on ExploitDB, and it has garnered significant community discussion and media coverage, indicating its relevance despite being an older CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4.17CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.17:*:*:*:*:*:*:* | ||
2.4.18CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.18:*:*:*:*:*:*:* | ||
2.4.19CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.19:*:*:*:*:*:*:* | ||
2.4.20CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.20:*:*:*:*:*:*:* | ||
2.4.21CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.21:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: Incomplete handling of LimitRequestFields directive in mod_http2
Dec 4, 2016Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project