Vulnerability record · CVE-2017-9798 · published 18 September 2017
CVE-2017-9798: Apache httpd use-after-free in Limit handling leaks process memory
Apache · Http Server
Apache httpd has a use-after-free in the ap_limit_section function that can be triggered when the Limit directive is set in a user's .htaccess file or when httpd.conf is misconfigured. A remote unauthenticated attacker can send an OPTIONS request and read secret data from process memory, a flaw known as Optionsbleed. It affects Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27.
Description
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27. The attacker sends an unauthenticated OPTIONS HTTP request when attempting to read secret data. This is a use-after-free issue and thus secret data is not always sent, and the specific data depends on many factors including configuration. Exploitation with .htaccess can be blocked with a patch to the ap_limit_section function in server/core.c.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityCVSS 3.1 base score is 7.5 (HIGH) with network reachability, no privileges or user interaction, and high confidentiality impact, and EPSS is near the top percentile.
What it is
Apache httpd has a use-after-free in the ap_limit_section function that can be triggered when the Limit directive is set in a user's .htaccess file or when httpd.conf is misconfigured. A remote unauthenticated attacker can send an OPTIONS request and read secret data from process memory, a flaw known as Optionsbleed. It affects Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27.
Impact
An attacker can read fragments of server process memory, potentially exposing secrets such as credentials, session data or other sensitive values. Because the leak is a use-after-free, data is not always returned and the specific contents depend on configuration and runtime state.
Attack surface
Reachable over the network via an unauthenticated HTTP OPTIONS request; no authentication or user interaction is required per the CVSS vector. Exploitation via .htaccess requires that file to be writable by a user and the Limit directive to be settable there, or a specific httpd.conf misconfiguration.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.94999 probability, 0.99858 percentile) and references include Exploit and Technical Description tags, indicating public exploit detail exists. No ransomware groups are documented as using it.
What to do
- Upgrade Apache HTTP Server to a version containing the fix for ap_limit_section in server/core.c (2.2.35 or later, 2.4.28 or later).
- Apply vendor patches or backports from Debian, Red Hat, Oracle or the upstream commit referenced in the advisory.
- Disable or restrict the Limit directive in .htaccess files, and review httpd.conf for misconfigurations that allow it.
- Where feasible, block or filter the OPTIONS HTTP method at the perimeter or reverse proxy.
- Audit .htaccess write permissions so untrusted users cannot set Limit directives.
Detection
- Monitor web server logs for unusual or repeated OPTIONS requests, especially from single sources.
- Inspect HTTP responses to OPTIONS requests for unexpected or anomalous content that may indicate memory leakage.
- Review .htaccess files and httpd.conf for Limit directive usage and unexpected changes.
- Track Apache httpd versions in inventory and alert on hosts still running 2.2.x through 2.2.34 or 2.4.x through 2.4.27.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-9798 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-9798), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.