Vulnerability record · CVE-2018-1303 · published 26 March 2018
CVE-2018-1303: Apache HTTP Server mod_cache_socache out-of-bounds read DoS
Apache · Http Server
A crafted HTTP request header triggers an out-of-bounds read in Apache HTTP Server before 2.4.30 while preparing data for caching in shared memory. The flaw affects only mod_cache_socache and can crash the server, causing denial of service. Apache rates it low risk because mod_cache_socache is not widely deployed; mod_cache_disk is unaffected.
Description
A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared memory. It could be used as a Denial of Service attack against users of mod_cache_socache. The vulnerability is considered as low risk since mod_cache_socache is not widely used, mod_cache_disk is not concerned by this vulnerability.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
medium priorityThe flaw is remotely triggerable with no authentication and causes denial of service, but it only affects the uncommon mod_cache_socache module and no active exploitation is documented.
What it is
A crafted HTTP request header triggers an out-of-bounds read in Apache HTTP Server before 2.4.30 while preparing data for caching in shared memory. The flaw affects only mod_cache_socache and can crash the server, causing denial of service. Apache rates it low risk because mod_cache_socache is not widely deployed; mod_cache_disk is unaffected.
Impact
An unauthenticated remote attacker can crash the Apache HTTP Server process, denying service to legitimate users. No data confidentiality or integrity impact is described; the effect is availability only.
Attack surface
Reachable over the network by sending a specially crafted HTTP request header to a server running mod_cache_socache. The CVSS vector shows no privileges and no user interaction required, so any client that can reach the HTTP listener can attempt it.
Exploitation
Not listed in CISA KEV and no ransomware usage documented; EPSS is high (about 0.70, 99th percentile), but references are advisories and vendor errata only, with no public exploit or in-the-wild activity noted.
What to do
- Upgrade Apache HTTP Server to 2.4.30 or later, or apply the vendor patch for your distribution.
- If mod_cache_socache is enabled and cannot be patched immediately, disable it and use mod_cache_disk instead, which is not affected.
- Apply the relevant vendor errata (Red Hat RHSA-2018:3558, RHSA-2019:0366/0367; Debian DSA-4164; Ubuntu USN-3627-1/2) for packaged builds.
- Check NetApp and HPE product advisories for bundled Apache versions and update those components.
- Restrict or monitor external access to HTTP endpoints that use shared-memory caching.
Detection
- Monitor Apache error and crash logs for segfaults or abnormal child process termination correlated with cache activity.
- Alert on repeated HTTP 5xx responses or connection resets from servers configured with mod_cache_socache.
- Audit Apache configuration files for CacheSocache or mod_cache_socache directives to identify exposed instances.
- Watch for unusual or malformed request headers hitting cache-enabled virtual hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-1303 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-1303), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.