← Vulnerability feed

Vulnerability record · CVE-2017-7668 · published 20 June 2017

CVE-2017-7668: Apache httpd token list parsing out-of-bounds read in ap_find_token()

Apache · Http Server

Apache httpd 2.2.32 and 2.4.24 introduced HTTP strict parsing changes that broke token list parsing, letting ap_find_token() read past the end of its input string. A crafted sequence of request headers can trigger a segmentation fault or make ap_find_token() return an incorrect value. This matters because it is remotely reachable without authentication and can crash the server or corrupt parsing decisions.

7.5 CVSS 3.1 High EPSS 57% · top 0.9% CWE-126 · CWE-126CWE-125 · Out-of-bounds read
7.5CVSS 3.1 base score, v2 5.0
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
13Affected product versions listed by NVD
70References
17 Jun 2026Last modified by NVD

Description

The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force ap_find_token() to return an incorrect value.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS 7.5 with network reachability, no authentication, and high EPSS indicate a serious denial-of-service risk, though no known exploitation is documented.

What it is

Apache httpd 2.2.32 and 2.4.24 introduced HTTP strict parsing changes that broke token list parsing, letting ap_find_token() read past the end of its input string. A crafted sequence of request headers can trigger a segmentation fault or make ap_find_token() return an incorrect value. This matters because it is remotely reachable without authentication and can crash the server or corrupt parsing decisions.

Impact

An attacker can cause a denial of service via segmentation fault, or force incorrect token parsing results that may affect request handling decisions. No confidentiality or integrity impact is described in the record.

Attack surface

Reached over the network by sending crafted HTTP request headers to an affected Apache httpd instance. The CVSS vector shows no privileges required and no user interaction.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented. EPSS is high at 0.57472 (99th percentile), and references include vendor advisories and patches but no public exploit tag.

What to do

  • Upgrade Apache httpd to a version that includes the fix for the token list parsing bug; apply the vendor patch referenced in the advisories.
  • Apply distribution and vendor errata for Red Hat, Debian, Oracle, NetApp, and Apple products that bundle affected httpd versions.
  • If immediate patching is not possible, restrict or filter untrusted HTTP request headers at a reverse proxy or WAF where feasible.
  • Monitor httpd processes for unexpected crashes and restart or fail over as needed to limit denial-of-service impact.

Detection

  • Monitor Apache httpd error logs and system logs for segmentation faults or abnormal child process crashes.
  • Alert on repeated HTTP requests with unusual or malformed header sequences that correlate with httpd restarts.
  • Use process monitoring to detect unexpected termination of httpd worker processes.
  • Review proxy or WAF logs for header patterns that trigger server errors or connection resets.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.debian.org/security/2017/dsa-3896 Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html PatchThird Party Advisory
http://www.securityfocus.com/bid/99137 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1038711 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2017:2479 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2483 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3193 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3194 Third Party Advisory
https://lists.apache.org/thread.html/55a068b6a5eec0b3198ae7d96a7cb412352d0ffa7716612c5af3745b%40%3Cdev.httpd.apache.org%
https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%
https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%
https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%
https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%
https://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935e2a0a6876dad3c%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r6521a7f62276340eabdb3339b2aa9a38c5f59d978497a1f794af53be%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/rfcf929bd33a6833e3f0c35eebdad70d5060665f9c4e17ea467c66770%40%3Ccvs.httpd.apache.org
https://security.gentoo.org/glsa/201710-32 Third Party Advisory
https://security.netapp.com/advisory/ntap-20180601-0002/ Third Party Advisory
https://support.apple.com/HT208221 Third Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03821en_us Third Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03908en_us Third Party Advisory
https://www.tenable.com/security/tns-2019-09 Third Party Advisory
http://www.debian.org/security/2017/dsa-3896 Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html PatchThird Party Advisory
http://www.securityfocus.com/bid/99137 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1038711 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2017:2479 Third Party Advisory

Track CVE-2017-7668 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2023-46604Apache ActiveMQ OpenWire deserialization remote code executionThe Java OpenWire protocol marshaller in Apache ActiveMQ deserializes untrusted data, letting an attacker manipulate serialized class types so the br…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2017-7668), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.