Vulnerability record · CVE-2011-3192 · published 29 August 2011
CVE-2011-3192: Apache HTTP Server byterange filter denial of service via overlapping Range headers
Apache · Http Server
The byterange filter in Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 mishandles a Range header that specifies multiple overlapping ranges, causing excessive memory and CPU consumption. This is a remotely reachable denial-of-service flaw that was exploited in the wild in August 2011.
Description
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
AV:N/AC:L/Au:N/C:N/I:N/A:C
Automated analysis
high priorityUnauthenticated remote denial of service with confirmed in-the-wild exploitation and very high EPSS, though impact is availability-only.
What it is
The byterange filter in Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 mishandles a Range header that specifies multiple overlapping ranges, causing excessive memory and CPU consumption. This is a remotely reachable denial-of-service flaw that was exploited in the wild in August 2011.
Impact
An unauthenticated remote attacker can exhaust server memory and CPU, degrading or taking down the HTTP service for legitimate users.
Attack surface
Reached over the network by sending a crafted HTTP request with a Range header containing multiple overlapping ranges; no authentication or user interaction is required per the AV:N/AC:L/Au:N vector.
Exploitation
The description states it was exploited in the wild in August 2011 and a reference is tagged Exploit, while CISA KEV does not list it; EPSS is very high at 0.98828 (99.925th percentile).
What to do
- Upgrade to a fixed Apache HTTP Server release for your branch (1.3.x, 2.0.x, or 2.2.x) as directed by the vendor advisory.
- If immediate patching is not possible, apply the vendor-recommended configuration workaround to limit or reject abusive Range requests.
- Apply distribution security updates from SUSE/openSUSE, Canonical, and other listed vendors.
- Restrict or rate-limit HTTP access to trusted networks where feasible to reduce exposure.
- Monitor server memory and CPU for anomalies during HTTP request bursts.
Detection
- Inspect HTTP access logs for requests containing Range headers with many or overlapping byte ranges.
- Alert on sudden spikes in memory and CPU usage on Apache HTTP Server hosts.
- Correlate repeated large-range requests from single source IPs with service degradation.
- Review web server error and performance logs for resource exhaustion patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-3192 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-3192), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.