Vulnerability record · CVE-2004-0942 · published 9 February 2005
CVE-2004-0942: Apache HTTP Server MIME header parsing CPU exhaustion DoS
Apache · Http Server
Apache HTTP Server 2.0.52 and earlier consumes excessive CPU when handling an HTTP GET request whose MIME header contains multiple lines filled with large numbers of space characters. The flaw is a denial-of-service condition in header parsing, and the record does not name the specific parsing routine or the exact fix. Because the request is unauthenticated and trivially crafted, any reachable web listener is exposed.
Description
Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityUnauthenticated remote availability impact with high EPSS but only partial impact and no confirmed exploit or KEV listing, on a long-obsolete Apache version.
What it is
Apache HTTP Server 2.0.52 and earlier consumes excessive CPU when handling an HTTP GET request whose MIME header contains multiple lines filled with large numbers of space characters. The flaw is a denial-of-service condition in header parsing, and the record does not name the specific parsing routine or the exact fix. Because the request is unauthenticated and trivially crafted, any reachable web listener is exposed.
Impact
A remote attacker can drive CPU consumption on the server, degrading or denying service to legitimate clients. There is no confidentiality or integrity impact; only availability is affected.
Attack surface
Reached over the network by sending a crafted HTTP GET request with a malformed multi-line MIME header to the web server. No authentication and no user interaction are required, per the AV:N/AC:L/Au:N vector.
Exploitation
Not listed in CISA KEV and no reference is tagged as exploit code, but EPSS is 0.55105 (99th percentile), indicating a high modeled likelihood of exploitation activity. The record does not confirm public exploit availability.
What to do
- Upgrade Apache HTTP Server past 2.0.52 to a vendor-supported release; this is the primary fix.
- If upgrade is not immediately possible, apply the relevant vendor errata (Red Hat RHSA-2004-562, Mandriva MDKSA-2004:135, Trustix, Sun, HP, Avaya advisories) for backported fixes.
- Front the server with a reverse proxy or WAF rule that rejects or normalizes HTTP headers containing excessive whitespace or abnormal line counts.
- Enforce request header size and count limits at the web server or load balancer to bound parsing work.
- Monitor CPU saturation on internet-facing Apache instances and rate-limit abusive source IPs as a stopgap.
Detection
- Alert on sustained CPU saturation on Apache hosts correlated with a spike in inbound GET requests.
- Inspect web access logs for GET requests with unusually long or whitespace-heavy headers, where header logging is enabled.
- Use packet capture or a proxy to flag HTTP requests whose MIME headers contain many lines of repeated space characters.
- Baseline normal request header sizes and alert on outliers exceeding that baseline.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0942 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0942), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.