CVE-2018-17189

In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connections.

Published: 2019-01-30 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2018-17189 is rated Moderate Risk (54.5/100): CVSS Medium severity, with high exploitation likelihood (EPSS 19.40%, 97th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2018-17189

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-19 20.07% 19.40% -0.67%
2 2026-06-15 7.67% 20.07% +12.40%
3 2026-04-29 7.67%

Full EPSS history (42 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2018-17189

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.3 3.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:L)
Might cause slowdowns, glitches, or partial disruption—not a full brick.
3.9 1.4 [email protected]
5.0 2.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:P)
Partial availability impact.
10.0 2.9 [email protected]

Weakness enumeration for CVE-2018-17189

OS Trackers for CVE-2018-17189

vendor priority summary link
alpine medium CVE-2018-17189: 1 source package rows (apache2); 10 state rows across 10 repos (3.10-main, 3.11-main, 3.12-main, 3.17-main, 3.18-main, 3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-main); fixed 10, open 0. https://security.alpinelinux.org/vuln/CVE-2018-17189
debian low CVE-2018-17189 low priority: Debian including 1 source packages (apache2), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2018-17189
gentoo normal CVE-2018-17189: 1 GLSA(s) (201903-21), 1 atom(s) (www-servers/apache); latest impact normal. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2018-17189
redhat low https://access.redhat.com/security/cve/CVE-2018-17189
suse medium CVE-2018-17189 severity moderate: SUSE including 47 source package names (apache2, apache2-2.4.23-29.34.4, …), 110 product×package rows across 25 product lines (SLES for SAP Applications 11 SP3, SUSE Liberty Linux 8, … (25 product lines)): Fixed 84, Known Not Affected 26. https://www.suse.com/security/cve/CVE-2018-17189/
ubuntu low CVE-2018-17189 low priority: Ubuntu including 1 source packages (apache2), 5 status rows across 5 suites (bionic, cosmic, trusty, upstream, xenial): released 3, not-affected 2. https://ubuntu.com/security/CVE-2018-17189

Affected software / configurations for CVE-2018-17189

Vendor Product Version Raw CPE
apache http_server 2.4.17 cpe:2.3:a:apache:http_server:2.4.17:*:*:*:*:*:*:*
apache http_server 2.4.18 cpe:2.3:a:apache:http_server:2.4.18:*:*:*:*:*:*:*
apache http_server 2.4.20 cpe:2.3:a:apache:http_server:2.4.20:*:*:*:*:*:*:*
apache http_server 2.4.23 cpe:2.3:a:apache:http_server:2.4.23:*:*:*:*:*:*:*
apache http_server 2.4.25 cpe:2.3:a:apache:http_server:2.4.25:*:*:*:*:*:*:*
apache http_server 2.4.26 cpe:2.3:a:apache:http_server:2.4.26:*:*:*:*:*:*:*
apache http_server 2.4.27 cpe:2.3:a:apache:http_server:2.4.27:*:*:*:*:*:*:*
apache http_server 2.4.28 cpe:2.3:a:apache:http_server:2.4.28:*:*:*:*:*:*:*
apache http_server 2.4.29 cpe:2.3:a:apache:http_server:2.4.29:*:*:*:*:*:*:*
apache http_server 2.4.30 cpe:2.3:a:apache:http_server:2.4.30:*:*:*:*:*:*:*
apache http_server 2.4.33 cpe:2.3:a:apache:http_server:2.4.33:*:*:*:*:*:*:*
apache http_server 2.4.34 cpe:2.3:a:apache:http_server:2.4.34:*:*:*:*:*:*:*
apache http_server 2.4.35 cpe:2.3:a:apache:http_server:2.4.35:*:*:*:*:*:*:*
apache http_server 2.4.37 cpe:2.3:a:apache:http_server:2.4.37:*:*:*:*:*:*:*
netapp santricity_cloud_connector cpe:2.3:a:netapp:santricity_cloud_connector:-:*:*:*:*:*:*:*
netapp storage_automation_store cpe:2.3:a:netapp:storage_automation_store:-:*:*:*:*:*:*:*
fedoraproject fedora 28 cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*
fedoraproject fedora 29 cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
debian debian_linux 9.0 cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
oracle enterprise_manager_ops_center 12.3.3 cpe:2.3:a:oracle:enterprise_manager_ops_center:12.3.3:*:*:*:*:*:*:*
oracle hospitality_guest_access 4.2.0 cpe:2.3:a:oracle:hospitality_guest_access:4.2.0:*:*:*:*:*:*:*
oracle hospitality_guest_access 4.2.1 cpe:2.3:a:oracle:hospitality_guest_access:4.2.1:*:*:*:*:*:*:*
oracle instantis_enterprisetrack 17.1 cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*
oracle instantis_enterprisetrack 17.2 cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:*
oracle instantis_enterprisetrack 17.3 cpe:2.3:a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:*
oracle retail_xstore_point_of_service 7.0 cpe:2.3:a:oracle:retail_xstore_point_of_service:7.0:*:*:*:*:*:*:*
oracle retail_xstore_point_of_service 7.1 cpe:2.3:a:oracle:retail_xstore_point_of_service:7.1:*:*:*:*:*:*:*
oracle sun_zfs_storage_appliance_kit 8.8.6 cpe:2.3:a:oracle:sun_zfs_storage_appliance_kit:8.8.6:*:*:*:*:*:*:*
canonical ubuntu_linux 14.04 cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
canonical ubuntu_linux 16.04 cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
canonical ubuntu_linux 18.04 cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
canonical ubuntu_linux 18.10 cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
redhat jboss_core_services 1.0 cpe:2.3:a:redhat:jboss_core_services:1.0:*:*:*:*:*:*:*

References for CVE-2018-17189

URL Tags
http://www.securityfocus.com/bid/106685 Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2019:3932 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3933 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3935 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:4126 Third Party Advisory
https://httpd.apache.org/security/vulnerabilities_24.html Vendor Advisory
https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E
https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E
https://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3E
https://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935e2a0a6876dad3c%40%3Ccvs.httpd.apache.org%3E
https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E
https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E
https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E
https://lists.apache.org/thread.html/rd2fb621142e7fa187cfe12d7137bf66e7234abcbbcd800074c84a538%40%3Ccvs.httpd.apache.org%3E
https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E
https://lists.apache.org/thread.html/re473305a65b4db888e3556e4dae10c2a04ee89dcff2e26ecdbd860a9%40%3Ccvs.httpd.apache.org%3E
https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IY7SJQOO3PYFVINZW6H5EK4EZ3HSGZNM/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U7N3DUEBFVGQWQEME5HTPTTKDHGHBAC6/
https://seclists.org/bugtraq/2019/Apr/5 Issue Tracking Mailing List Third Party Advisory
https://security.gentoo.org/glsa/201903-21 Third Party Advisory
https://security.netapp.com/advisory/ntap-20190125-0001/ Third Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03950en_us Third Party Advisory
https://usn.ubuntu.com/3937-1/ Third Party Advisory
https://www.debian.org/security/2019/dsa-4422 Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2020.html Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html Third Party Advisory
https://www.tenable.com/security/tns-2019-09 Third Party Advisory
cvelogic Threat Intelligence