Vulnerability record · CVE-2017-7668 · published 20 June 2017
CVE-2017-7668: Apache httpd token list parsing out-of-bounds read in ap_find_token()
Apache · Http Server
Apache httpd 2.2.32 and 2.4.24 introduced HTTP strict parsing changes that broke token list parsing, letting ap_find_token() read past the end of its input string. A crafted sequence of request headers can trigger a segmentation fault or make ap_find_token() return an incorrect value. This matters because it is remotely reachable without authentication and can crash the server or corrupt parsing decisions.
Description
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force ap_find_token() to return an incorrect value.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityCVSS 7.5 with network reachability, no authentication, and high EPSS indicate a serious denial-of-service risk, though no known exploitation is documented.
What it is
Apache httpd 2.2.32 and 2.4.24 introduced HTTP strict parsing changes that broke token list parsing, letting ap_find_token() read past the end of its input string. A crafted sequence of request headers can trigger a segmentation fault or make ap_find_token() return an incorrect value. This matters because it is remotely reachable without authentication and can crash the server or corrupt parsing decisions.
Impact
An attacker can cause a denial of service via segmentation fault, or force incorrect token parsing results that may affect request handling decisions. No confidentiality or integrity impact is described in the record.
Attack surface
Reached over the network by sending crafted HTTP request headers to an affected Apache httpd instance. The CVSS vector shows no privileges required and no user interaction.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented. EPSS is high at 0.57472 (99th percentile), and references include vendor advisories and patches but no public exploit tag.
What to do
- Upgrade Apache httpd to a version that includes the fix for the token list parsing bug; apply the vendor patch referenced in the advisories.
- Apply distribution and vendor errata for Red Hat, Debian, Oracle, NetApp, and Apple products that bundle affected httpd versions.
- If immediate patching is not possible, restrict or filter untrusted HTTP request headers at a reverse proxy or WAF where feasible.
- Monitor httpd processes for unexpected crashes and restart or fail over as needed to limit denial-of-service impact.
Detection
- Monitor Apache httpd error logs and system logs for segmentation faults or abnormal child process crashes.
- Alert on repeated HTTP requests with unusual or malformed header sequences that correlate with httpd restarts.
- Use process monitoring to detect unexpected termination of httpd worker processes.
- Review proxy or WAF logs for header patterns that trigger server errors or connection resets.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-7668 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-7668), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.