CVE-2025-49630: Apache HTTP Server: mod_proxy_http2 denial of service
In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in modproxyhttp2.
Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".
Other sources
In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in modproxyhttp2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to \"on\"
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49630?
CVE-2025-49630 has been classified as a denial of service vulnerability affecting specific Apache HTTP Server versions.
How do I fix CVE-2025-49630?
To mitigate CVE-2025-49630, upgrade your Apache HTTP Server to a version later than 2.4.63.
What versions of Apache HTTP Server are affected by CVE-2025-49630?
Apache HTTP Server versions 2.4.26 through 2.4.63 are affected by CVE-2025-49630.
What causes the vulnerability CVE-2025-49630?
CVE-2025-49630 can be triggered by untrusted clients in certain proxy configurations leading to an assertion failure in mod_proxy_http2.
Is my Apache HTTP Server setup at risk with CVE-2025-49630?
If you are running a version of Apache HTTP Server between 2.4.26 and 2.4.63 with a reverse proxy set up for an HTTP/2 backend, your setup is at risk.