← Vulnerability feed

Vulnerability record · CVE-2022-30522 · published 9 June 2022

CVE-2022-30522: Apache HTTP Server mod_sed unbounded allocation causes abort

Apache · Http Server

Apache HTTP Server 2.4.53 configured to use mod_sed for transformations can make excessively large memory allocations when the input to mod_sed is very large, triggering an abort. The flaw is an allocation-without-limits issue (CWE-789/CWE-770) that lets a remote request drive the process into a denial-of-service condition. It matters because mod_sed is a supported transformation module and the trigger is a normal network request.

7.5 CVSS 3.1 High EPSS 90% · top 0.2% CWE-789 · CWE-789CWE-770 · Allocation without limits
7.5CVSS 3.1 base score, v2 5.0
90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityRemote, unauthenticated availability impact with a very high EPSS score, though exploitation is limited to servers that configure mod_sed on large inputs.

What it is

Apache HTTP Server 2.4.53 configured to use mod_sed for transformations can make excessively large memory allocations when the input to mod_sed is very large, triggering an abort. The flaw is an allocation-without-limits issue (CWE-789/CWE-770) that lets a remote request drive the process into a denial-of-service condition. It matters because mod_sed is a supported transformation module and the trigger is a normal network request.

Impact

An attacker can cause the affected httpd process to abort, denying service to legitimate users. There is no confidentiality or integrity impact per the CVSS vector; only availability is affected.

Attack surface

Reachable over the network (AV:N) with no authentication (PR:N) and no user interaction (UI:N), but only on servers where mod_sed is configured to transform input that can be very large. Servers not using mod_sed in such contexts are not exposed.

Exploitation

Not listed in CISA KEV and no ransomware use is documented; EPSS is very high (0.89529, 99.8th percentile), and references are vendor and third-party advisories with no public exploit tag.

What to do

  • Upgrade Apache HTTP Server past 2.4.53 to a fixed release per the vendor advisory.
  • If mod_sed is not required, disable or remove the module from the configuration.
  • Where mod_sed must stay, avoid applying it to unbounded or very large inputs and cap request/body sizes.
  • Apply vendor updates for downstream products (NetApp Clustered Data ONTAP, Fedora) that bundle the affected httpd.
  • Monitor memory usage and process restarts on httpd hosts running mod_sed.

Detection

  • Alert on httpd process aborts or unexpected restarts on hosts with mod_sed enabled.
  • Track memory spikes and OOM events correlated with requests routed through mod_sed transformations.
  • Review httpd configuration to inventory where mod_sed is active and what input sizes it processes.
  • Watch for repeated large-body requests to endpoints handled by mod_sed.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-30522 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2024-4577PHP-CGI on Windows argument injection leads to remote code executionPHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windo…KEVEPSS 100%analysed9.8CVE-2021-44026Roundcube Webmail SQL injection via search parametersRoundcube Webmail before 1.3.17 and 1.4.x before 1.4.12 is prone to SQL injection through the search or search_params input. The flaw is remotely rea…KEVEPSS 70%analysed9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed9.8CVE-2021-41773Apache HTTP Server 2.4.49 path traversal and RCEA path normalization flaw introduced in Apache HTTP Server 2.4.49 lets attackers map URLs to files outside directories configured by Alias-like direc…KEVEPSS 100%analysed9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed9.8CVE-2021-1871Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions. It affects macOS Big Sur, Catalina, Mojave, iOS and iPadOS, and a remote at…KEVEPSS 7.0%analysed9.8CVE-2020-16846SaltStack Salt API shell injection via crafted web requestsSaltStack Salt through 3002 is vulnerable to OS command injection when the SSH client is enabled and crafted web requests are sent to the Salt API. T…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2022-30522), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.