Vulnerability record · CVE-2022-30522 · published 9 June 2022
CVE-2022-30522: Apache HTTP Server mod_sed unbounded allocation causes abort
Apache · Http Server
Apache HTTP Server 2.4.53 configured to use mod_sed for transformations can make excessively large memory allocations when the input to mod_sed is very large, triggering an abort. The flaw is an allocation-without-limits issue (CWE-789/CWE-770) that lets a remote request drive the process into a denial-of-service condition. It matters because mod_sed is a supported transformation module and the trigger is a normal network request.
Description
If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityRemote, unauthenticated availability impact with a very high EPSS score, though exploitation is limited to servers that configure mod_sed on large inputs.
What it is
Apache HTTP Server 2.4.53 configured to use mod_sed for transformations can make excessively large memory allocations when the input to mod_sed is very large, triggering an abort. The flaw is an allocation-without-limits issue (CWE-789/CWE-770) that lets a remote request drive the process into a denial-of-service condition. It matters because mod_sed is a supported transformation module and the trigger is a normal network request.
Impact
An attacker can cause the affected httpd process to abort, denying service to legitimate users. There is no confidentiality or integrity impact per the CVSS vector; only availability is affected.
Attack surface
Reachable over the network (AV:N) with no authentication (PR:N) and no user interaction (UI:N), but only on servers where mod_sed is configured to transform input that can be very large. Servers not using mod_sed in such contexts are not exposed.
Exploitation
Not listed in CISA KEV and no ransomware use is documented; EPSS is very high (0.89529, 99.8th percentile), and references are vendor and third-party advisories with no public exploit tag.
What to do
- Upgrade Apache HTTP Server past 2.4.53 to a fixed release per the vendor advisory.
- If mod_sed is not required, disable or remove the module from the configuration.
- Where mod_sed must stay, avoid applying it to unbounded or very large inputs and cap request/body sizes.
- Apply vendor updates for downstream products (NetApp Clustered Data ONTAP, Fedora) that bundle the affected httpd.
- Monitor memory usage and process restarts on httpd hosts running mod_sed.
Detection
- Alert on httpd process aborts or unexpected restarts on hosts with mod_sed enabled.
- Track memory spikes and OOM events correlated with requests routed through mod_sed transformations.
- Review httpd configuration to inventory where mod_sed is active and what input sizes it processes.
- Watch for repeated large-body requests to endpoints handled by mod_sed.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-30522 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-30522), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.