CVE-2017-7659 describes a NULL pointer dereference vulnerability in mod_http2 of Apache HTTP Server versions 2.4.24 and 2.4.25, triggered by a maliciously crafted HTTP/2 request. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating it can be exploited remotely with low complexity and no user interaction, leading to a denial of service by crashing the server process. Despite its high severity and potential for server disruption, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, with only one mention and one article, the latter incorrectly linking to a different CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4.24CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.24:*:*:*:*:*:*:* | ||
2.4.25CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.25:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: mod_http2 NULL pointer dereference
Jun 20, 2017Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project