Vulnerability record · CVE-2022-23943 · published 14 March 2022
CVE-2022-23943: Apache HTTP Server mod_sed heap out-of-bounds write
Apache · Http Server
mod_sed in Apache HTTP Server 2.4.52 and earlier contains an out-of-bounds write (linked to an integer overflow) that lets an attacker overwrite heap memory with possibly attacker-controlled data. Because mod_sed processes request content, a remote unauthenticated attacker can reach the flaw over the network, making it a serious memory-corruption issue for exposed servers.
Description
Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCritical CVSS (9.8) with network reachability and no authentication, but no confirmed in-the-wild exploitation or KEV listing keeps it below critical.
What it is
mod_sed in Apache HTTP Server 2.4.52 and earlier contains an out-of-bounds write (linked to an integer overflow) that lets an attacker overwrite heap memory with possibly attacker-controlled data. Because mod_sed processes request content, a remote unauthenticated attacker can reach the flaw over the network, making it a serious memory-corruption issue for exposed servers.
Impact
An attacker can corrupt heap memory with data they influence, which can lead to process crashes and, depending on heap layout, remote code execution in the context of the httpd process.
Attack surface
Reached over the network via HTTP requests handled by mod_sed; the CVSS vector shows no privileges and no user interaction required, so any client that can send requests to an affected server can attempt it.
Exploitation
Not listed in CISA KEV and no ransomware use documented, but EPSS is high (0.504 probability, 98.9th percentile), indicating elevated likelihood of attempted exploitation; references are advisories and patches, with no public exploit tag.
What to do
- Upgrade Apache HTTP Server to a version later than 2.4.52 that contains the mod_sed fix.
- If mod_sed is not required, disable or do not load the module to remove the attack surface.
- Apply vendor patches for downstream packages (Debian, Fedora, Oracle, NetApp, Gentoo) where the affected httpd build is bundled.
- Restrict or monitor external exposure of httpd instances that load mod_sed until patching is complete.
Detection
- Monitor httpd logs for crashes, restarts or abnormal child process exits that could indicate heap corruption.
- Watch for unusual or oversized request bodies and filter patterns targeting mod_sed directives.
- Use host or container memory-corruption detections (ASAN builds, EDR crash telemetry) on httpd processes.
- Track version inventory to flag any httpd 2.4.52 or earlier still running with mod_sed enabled.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-23943 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-23943), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.