← Vulnerability feed

Vulnerability record · CVE-2017-9798 · published 18 September 2017

CVE-2017-9798: Apache httpd use-after-free in Limit handling leaks process memory

Apache · Http Server

Apache httpd has a use-after-free in the ap_limit_section function that can be triggered when the Limit directive is set in a user's .htaccess file or when httpd.conf is misconfigured. A remote unauthenticated attacker can send an OPTIONS request and read secret data from process memory, a flaw known as Optionsbleed. It affects Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27.

7.5 CVSS 3.1 High EPSS 95% · top 0.1% CWE-416 · Use after free
7.5CVSS 3.1 base score, v2 5.0
95%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
111References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27. The attacker sends an unauthenticated OPTIONS HTTP request when attempting to read secret data. This is a use-after-free issue and thus secret data is not always sent, and the specific data depends on many factors including configuration. Exploitation with .htaccess can be blocked with a patch to the ap_limit_section function in server/core.c.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS 3.1 base score is 7.5 (HIGH) with network reachability, no privileges or user interaction, and high confidentiality impact, and EPSS is near the top percentile.

What it is

Apache httpd has a use-after-free in the ap_limit_section function that can be triggered when the Limit directive is set in a user's .htaccess file or when httpd.conf is misconfigured. A remote unauthenticated attacker can send an OPTIONS request and read secret data from process memory, a flaw known as Optionsbleed. It affects Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27.

Impact

An attacker can read fragments of server process memory, potentially exposing secrets such as credentials, session data or other sensitive values. Because the leak is a use-after-free, data is not always returned and the specific contents depend on configuration and runtime state.

Attack surface

Reachable over the network via an unauthenticated HTTP OPTIONS request; no authentication or user interaction is required per the CVSS vector. Exploitation via .htaccess requires that file to be writable by a user and the Limit directive to be settable there, or a specific httpd.conf misconfiguration.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.94999 probability, 0.99858 percentile) and references include Exploit and Technical Description tags, indicating public exploit detail exists. No ransomware groups are documented as using it.

What to do

  • Upgrade Apache HTTP Server to a version containing the fix for ap_limit_section in server/core.c (2.2.35 or later, 2.4.28 or later).
  • Apply vendor patches or backports from Debian, Red Hat, Oracle or the upstream commit referenced in the advisory.
  • Disable or restrict the Limit directive in .htaccess files, and review httpd.conf for misconfigurations that allow it.
  • Where feasible, block or filter the OPTIONS HTTP method at the perimeter or reverse proxy.
  • Audit .htaccess write permissions so untrusted users cannot set Limit directives.

Detection

  • Monitor web server logs for unusual or repeated OPTIONS requests, especially from single sources.
  • Inspect HTTP responses to OPTIONS requests for unexpected or anomalous content that may indicate memory leakage.
  • Review .htaccess files and httpd.conf for Limit directive usage and unexpected changes.
  • Track Apache httpd versions in inventory and alert on hosts still running 2.2.x through 2.2.34 or 2.4.x through 2.4.27.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://openwall.com/lists/oss-security/2017/09/18/2 Mailing ListVDB Entry
http://www.debian.org/security/2017/dsa-3980 Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html PatchThird Party Advisory
http://www.securityfocus.com/bid/100872 Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/105598 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1039387 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2017:2882 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2972 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3018 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3113 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3114 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3193 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3194 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3195 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3239 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3240 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3475 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3476 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3477 Third Party Advisory
https://blog.fuzzing-project.org/60-Optionsbleed-HTTP-OPTIONS-method-can-leak-Apaches-server-memory.html ExploitPatchTechnical DescriptionThird Party Advisory
https://blog.fuzzing-project.org/uploads/apache-2.2-optionsbleed-backport.patch ExploitPatchTechnical DescriptionThird Party Advisory
https://github.com/apache/httpd/commit/4cc27823899e070268b906ca677ee838d07cf67a PatchVendor Advisory
https://github.com/hannob/optionsbleed ExploitThird Party Advisory
https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2017-9798 Vendor Advisory
https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%
https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%
https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%
https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%
https://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935e2a0a6876dad3c%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r6521a7f62276340eabdb3339b2aa9a38c5f59d978497a1f794af53be%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org

Track CVE-2017-9798 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2023-46604Apache ActiveMQ OpenWire deserialization remote code executionThe Java OpenWire protocol marshaller in Apache ActiveMQ deserializes untrusted data, letting an attacker manipulate serialized class types so the br…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2017-9798), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.