Vulnerability record · CVE-2019-0190 · published 30 January 2019
CVE-2019-0190: Apache HTTP Server mod_ssl renegotiation loop denial of service
Apache · Http Server
A bug in mod_ssl's handling of client renegotiations lets a remote attacker send a crafted request that drives mod_ssl into a loop, causing a denial of service. It only triggers on Apache HTTP Server 2.4.37 combined with OpenSSL 1.1.1 or later, so exposure is limited to that specific pairing. The flaw is availability-only; there is no confidentiality or integrity impact.
Description
A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only triggered with Apache HTTP Server version 2.4.37 when using OpenSSL version 1.1.1 or later, due to an interaction in changes to handling of renegotiation attempts.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityUnauthenticated network-reachable denial of service with a high EPSS score, though limited to a narrow Apache 2.4.37 plus OpenSSL 1.1.1+ configuration and not observed in KEV.
What it is
A bug in mod_ssl's handling of client renegotiations lets a remote attacker send a crafted request that drives mod_ssl into a loop, causing a denial of service. It only triggers on Apache HTTP Server 2.4.37 combined with OpenSSL 1.1.1 or later, so exposure is limited to that specific pairing. The flaw is availability-only; there is no confidentiality or integrity impact.
Impact
An unauthenticated remote attacker can exhaust server resources and make the affected Apache instance stop serving requests, denying service to legitimate users.
Attack surface
Reached over the network via the TLS/HTTPS listener on an affected Apache 2.4.37 plus OpenSSL 1.1.1+ deployment. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV and no ransomware usage documented, but EPSS is high at roughly 0.59 probability (99th percentile), indicating meaningful predicted exploitation activity; references are vendor and third-party advisories only, with no public exploit tag.
What to do
- Upgrade Apache HTTP Server past 2.4.37 to a release where the mod_ssl renegotiation handling is fixed, per the Apache vendor advisory.
- If immediate upgrade is not possible, avoid the 2.4.37 plus OpenSSL 1.1.1+ combination by reverting to an earlier OpenSSL or Apache build.
- Disable or restrict client-initiated renegotiation (SSLInsecureRenegotiation off / SSLVerifyClient settings) where the deployment allows it.
- Apply vendor patches for downstream products that bundle the affected Apache build, such as Oracle advisories listed in the references.
- Rate-limit or front the TLS endpoint with a proxy that can absorb or drop renegotiation floods.
Detection
- Monitor Apache error and access logs for repeated TLS renegotiation or handshake failures from single sources.
- Alert on spikes in CPU or worker/connection saturation on Apache 2.4.37 hosts with OpenSSL 1.1.1+.
- Track TLS handshake and renegotiation counts per client IP to spot loop-inducing request patterns.
- Inventory Apache and OpenSSL versions to confirm which hosts match the vulnerable 2.4.37 plus 1.1.1+ combination.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-0190 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-0190), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.