Appsecure logo

CVE-2023-45802: Medium Vulnerability in Apache HTTP Server

A medium-severity vulnerability in Apache HTTP Server could lead to memory leaks due to improper handling of HTTP/2 stream resets. This vulnerability requires immediate attention and patching to prevent potential service disruptions.

MEDIUMCVSS 5.9 · Published October 23, 2023

Not a customer? See how AppSecure simulates real world attacks to protect your infrastructure.

Speak to Experts

CVE-2023-45802 is a medium-severity vulnerability affecting the Apache HTTP Server. This vulnerability allows for a memory leak during the handling of HTTP/2 stream resets (RST frames) by clients. When a client resets an HTTP/2 stream, there is a time window where the request's memory resources are not reclaimed immediately, which could lead to increased memory usage and potential service disruption.

The CVSS score for this vulnerability is 5.9, indicating a medium level of risk. The attack vector is network-based, and the attack complexity is classified as high, meaning that successful exploitation may require advanced knowledge or capabilities. While the probability of encountering this bug in normal HTTP/2 usage is low, organizations must remain vigilant to prevent potential memory exhaustion.

Organizations should prioritize patching immediately. The recommended version to upgrade to is 2.4.58, which addresses this vulnerability. Failure to apply the patch could result in increased memory usage and eventual denial of service.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Latest CVEs. Recently published vulnerabilities from the NVD database.

View all vulnerabilities
CVE IDSeverity
CVE-2025-65418HIGH
CVE-2025-65417MEDIUM
CVE-2025-65416MEDIUM
CVE-2025-65415MEDIUM
CVE-2025-61314HIGH

Protect Your Business with Hacker-Focused Approach.