Endpoint Vulnerability

Apache Httpd - low:mod_http2: denial of service by thread starvation(CVE-2016-1546)


By manipulating the flow control windows on streams, a client was able to block server threads for long times, causing starvation of worker threads. Connections could still be opened, but no streams where processed for these. This issue affected HTTP/2 support in 2.4.17 and 2.4.18.

Affected Products

Apache Httpd