Vulnerability record · CVE-2018-11763 · published 25 September 2018
CVE-2018-11763: Apache HTTP Server HTTP/2 SETTINGS frame denial of service
Apache · Http Server
Apache HTTP Server 2.4.17 through 2.4.34 fails to time out connections when a client sends continuous large HTTP/2 SETTINGS frames. Each such connection permanently occupies a server thread and CPU time, so a client can exhaust server capacity. Only HTTP/2 (h2) connections are affected.
Description
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityThe flaw is remotely reachable without authentication and causes availability loss, and EPSS is high despite no KEV listing.
What it is
Apache HTTP Server 2.4.17 through 2.4.34 fails to time out connections when a client sends continuous large HTTP/2 SETTINGS frames. Each such connection permanently occupies a server thread and CPU time, so a client can exhaust server capacity. Only HTTP/2 (h2) connections are affected.
Impact
An unauthenticated remote attacker can tie up server threads and CPU indefinitely, degrading or denying service to legitimate users. There is no confidentiality or integrity impact; the effect is availability loss.
Attack surface
Reachable over the network on any HTTP/2-enabled listener; no authentication and no user interaction are required, though the CVSS vector rates attack complexity as high. The flaw is only exposed when the h2 protocol is enabled.
Exploitation
Not listed in CISA KEV and no ransomware use is documented, but EPSS is high at roughly 0.51 (98.9th percentile), indicating elevated likelihood of attempted exploitation. Reference tags are advisory and patch notices only, with no public exploit tag.
What to do
- Upgrade Apache HTTP Server to a version later than 2.4.34 that contains the fix.
- If immediate upgrade is not possible, disable the h2 protocol in the server configuration as the vendor-documented workaround.
- Apply vendor errata for packaged builds (Red Hat, Ubuntu, Oracle, NetApp, HPE) rather than relying on upstream source alone.
- Set connection and request timeouts and limit concurrent HTTP/2 connections per client to reduce the blast radius.
- Monitor HTTP/2-enabled endpoints for sustained connection counts and thread pool saturation.
Detection
- Alert on HTTP/2 connections that persist far beyond normal session duration or never complete.
- Track server thread pool and worker saturation metrics for sustained high occupancy tied to few clients.
- Log and correlate repeated large SETTINGS frames from the same source IP across many connections.
- Watch for a single client opening many concurrent h2 connections without corresponding request activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-11763 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-11763), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.