Vulnerability record · CVE-2003-0132 · published 11 April 2003
CVE-2003-0132: Apache HTTP Server memory leak via linefeed flood causes DoS
Apache · Http Server
Apache HTTP Server 2.0 through 2.0.44 leaks memory when processing large chunks of linefeed characters, allocating roughly 80 bytes per linefeed. Repeated requests drive unbounded memory consumption, degrading or exhausting the server process. The record does not specify affected patch versions beyond the 2.0.44 upper bound.
Description
A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
high priorityUnauthenticated remote DoS with public exploit references and a very high EPSS score, though impact is limited to availability and the product line is long end-of-life.
What it is
Apache HTTP Server 2.0 through 2.0.44 leaks memory when processing large chunks of linefeed characters, allocating roughly 80 bytes per linefeed. Repeated requests drive unbounded memory consumption, degrading or exhausting the server process. The record does not specify affected patch versions beyond the 2.0.44 upper bound.
Impact
A remote unauthenticated attacker can exhaust server memory and cause a denial of service, taking the web server or its host process out of service.
Attack surface
Reachable over the network via HTTP requests containing large volumes of linefeed characters; no authentication or user interaction is required per the AV:N/AC:L/Au:N vector.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.86677, 99.73rd percentile) and one Bugtraq reference is tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade Apache HTTP Server past 2.0.44 to a fixed release; patch first.
- If immediate upgrade is not possible, apply vendor or distribution backports (e.g., Red Hat RHSA-2003-139) for the affected branch.
- Enforce request size and header/body limits at a reverse proxy or WAF to cap oversized linefeed payloads.
- Monitor and cap per-process memory with resource limits so a single worker cannot exhaust host memory.
- Retire or isolate end-of-life Apache 2.0.x deployments that cannot be patched.
Detection
- Alert on abnormal memory growth in httpd worker processes correlated with request volume.
- Inspect HTTP request logs for bodies or headers dominated by linefeed (0x0A) characters.
- Track repeated requests from single sources producing large request bodies with minimal other content.
- Watch for OOM-killer events or process restarts on web servers running Apache 2.0.x.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2003-0132 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-0132), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.