CVE-2023-45802 is a denial-of-service vulnerability affecting Apache HTTP Server versions, including those in Debian and Fedora distributions. It allows a remote attacker to exhaust memory resources by repeatedly sending and resetting HTTP/2 requests, preventing the server from reclaiming memory until the connection closes. This vulnerability has a medium severity CVSS score of 5.9, indicating a network attack vector with high attack complexity and high availability impact. While not currently listed on CISA's KEV catalog or having public exploit code, it has garnered some community discussion and media coverage, though the media coverage incorrectly links to a different CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.4.17, < 2.4.58CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server vulnerabilities
May 28, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025mod_http2: reset requests exhaust memory (incomplete fix of CVE-2023-44487)
Oct 19, 2023Apache HTTP Server: HTTP/2 stream memory not reclaimed right away on RST
Oct 10, 2023Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project