Description
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.
Published: 2018-09-25
Score: 5.9 Medium
EPSS: 17.4% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-3783-1 Apache HTTP Server vulnerabilities
References
Link Providers
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00030.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00056.html cve-icon cve-icon
http://www.securityfocus.com/bid/105414 cve-icon cve-icon
http://www.securitytracker.com/id/1041713 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2018:3558 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2019:0366 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2019:0367 cve-icon cve-icon
https://httpd.apache.org/security/vulnerabilities_24.html cve-icon cve-icon
https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935e2a0a6876dad3c%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r6521a7f62276340eabdb3339b2aa9a38c5f59d978497a1f794af53be%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rfcf929bd33a6833e3f0c35eebdad70d5060665f9c4e17ea467c66770%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2018-11763 cve-icon
https://security.netapp.com/advisory/ntap-20190204-0004/ cve-icon cve-icon
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03909en_us cve-icon cve-icon
https://usn.ubuntu.com/3783-1/ cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2018-11763 cve-icon
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html cve-icon cve-icon
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html cve-icon cve-icon
https://www.tenable.com/security/tns-2019-09 cve-icon cve-icon
History

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.19167}

epss

{'score': 0.18884}


Subscriptions

Apache Http Server
Canonical Ubuntu Linux
Netapp Storage Automation Store
Oracle Enterprise Manager Ops Center Hospitality Guest Access Instantis Enterprisetrack Retail Xstore Point Of Service Secure Global Desktop
Redhat Enterprise Linux Jboss Core Services Rhel Software Collections
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-09-17T02:21:55.083Z

Reserved: 2018-06-05T00:00:00.000Z

Link: CVE-2018-11763

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-09-25T21:29:00.283

Modified: 2024-11-21T03:43:58.790

Link: CVE-2018-11763

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-09-25T00:00:00Z

Links: CVE-2018-11763 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses