CVE-2018-1302 describes a NULL pointer dereference vulnerability in Apache HTTP Server versions prior to 2.4.30, specifically affecting HTTP/2 stream handling. This flaw could lead to a server crash due to writing a NULL pointer to potentially freed memory. The vulnerability is rated Medium severity (CVSS 5.9) with high attack complexity, meaning successful exploitation is difficult, and its primary impact is a denial of service. Despite its presence in Apache, Canonical, and NetApp products, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, indicating a low practical risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.4.29CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:santricity_cloud_connector:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:storage_automation_store:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: Use-after-free on HTTP/2 stream shutdown
Mar 21, 2018Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project