CVE-2019-0190 describes a denial-of-service vulnerability in Apache HTTP Server version 2.4.37 when used with OpenSSL 1.1.1 or later. A remote attacker can trigger a loop in mod_ssl by sending a specially crafted request during client renegotiation, leading to service disruption. This vulnerability has a CVSS score of 7.5 (HIGH) due to its network-based attack vector, low attack complexity, and high impact on availability. While there is no known public exploit code or active exploitation, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4.37CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.37:*:*:*:*:*:*:* | ||
12.3.3CPE matchmatch criteria | cpe:2.3:a:oracle:enterprise_manager_ops_center:12.3.3:*:*:*:*:*:*:* | ||
4.2.0CPE matchmatch criteria | cpe:2.3:a:oracle:hospitality_guest_access:4.2.0:*:*:*:*:*:*:* | ||
4.2.1CPE matchmatch criteria | cpe:2.3:a:oracle:hospitality_guest_access:4.2.1:*:*:*:*:*:*:* | ||
17.1CPE matchmatch criteria | cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: mod_ssl: infinite loop triggered by client-initiated renegotiation when using OpenSSL 1.1.1
Jan 22, 2019Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project