Vulnerability record · CVE-2007-6750 · published 27 December 2011
CVE-2007-6750: Apache HTTP Server Slowloris partial-request denial of service
Apache · Http Server
Apache HTTP Server 1.x and 2.x can be forced into a daemon outage by remote attackers sending partial HTTP requests, the technique known as Slowloris. The flaw stems from the absence of the mod_reqtimeout module in versions before 2.2.15, so slow or incomplete requests are never timed out and consume server connection slots.
Description
The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
high priorityThe flaw is trivially reachable and reliably causes service outage, and EPSS indicates a high likelihood of exploitation activity, though it is not in KEV.
What it is
Apache HTTP Server 1.x and 2.x can be forced into a daemon outage by remote attackers sending partial HTTP requests, the technique known as Slowloris. The flaw stems from the absence of the mod_reqtimeout module in versions before 2.2.15, so slow or incomplete requests are never timed out and consume server connection slots.
Impact
An attacker can exhaust the server's connection handling capacity and take the web service offline for legitimate users. No data is read or modified; the effect is availability loss.
Attack surface
Reachable over the network by sending many partial HTTP requests to the web listener; no authentication or user interaction is required, as reflected by the AV:N/AC:L/Au:N vector.
Exploitation
The technique is publicly documented (Slowloris) and EPSS is high at 0.70525 (99.36th percentile), but the CVE is not listed in CISA KEV and the references carry no exploit tags.
What to do
- Upgrade to Apache HTTP Server 2.2.15 or later, which includes mod_reqtimeout, or apply the vendor patch for your branch.
- Enable and tune mod_reqtimeout (RequestReadTimeout) to cap header and body read times.
- Front the server with a reverse proxy or load balancer that enforces its own request timeouts and connection limits.
- Reduce MaxClients/connection limits and set KeepAliveTimeout to limit the resources a single slow client can hold.
- Use connection-rate limiting or a DoS mitigation module to drop clients that open many idle connections.
Detection
- Monitor for many concurrent connections from few source IPs that remain open without completing a request.
- Alert on unusually long-lived connections or slow header/body transfer times in web server or proxy logs.
- Track spikes in connection count and request timeouts that coincide with service unavailability.
- Baseline normal concurrent connection levels and alert when they exceed expected thresholds.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-6750 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-6750), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.