{
    "id": "CVE-2017-9788",
    "published": "2017-07-13 16:29:00",
    "last_modified": "2026-06-17 01:28:54",
    "cvss_score": "9.1",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.0",
    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
    "cwe": "CWE-20",
    "description": "In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest. Providing an initial key with no '=' assignment could reflect the stale value of uninitialized pool memory used by the prior request, leading to leakage of potentially confidential information, and a segfault in other cases resulting in denial of service.",
    "epss_score": "0.56770",
    "epss_percentile": "0.99041",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-02 18:17:20",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "EPSS 56.8% — above the 10% action threshold."
    },
    "products": [
        {
            "vendor": "apache",
            "product": "http_server"
        },
        {
            "vendor": "apple",
            "product": "mac_os_x"
        },
        {
            "vendor": "debian",
            "product": "debian_linux"
        },
        {
            "vendor": "netapp",
            "product": "oncommand_unified_manager"
        },
        {
            "vendor": "netapp",
            "product": "storage_automation_store"
        },
        {
            "vendor": "oracle",
            "product": "secure_global_desktop"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_desktop"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_server"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_server_aus"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_server_eus"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_server_tus"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_workstation"
        },
        {
            "vendor": "redhat",
            "product": "jboss_core_services"
        },
        {
            "vendor": "redhat",
            "product": "jboss_enterprise_application_platform"
        },
        {
            "vendor": "redhat",
            "product": "jboss_enterprise_web_server"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "http://www.debian.org/security/2017/dsa-3913",
        "http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html",
        "http://www.securityfocus.com/bid/99569",
        "http://www.securitytracker.com/id/1038906",
        "https://access.redhat.com/errata/RHSA-2017:2478",
        "https://access.redhat.com/errata/RHSA-2017:2479",
        "https://access.redhat.com/errata/RHSA-2017:2483",
        "https://access.redhat.com/errata/RHSA-2017:2708",
        "https://access.redhat.com/errata/RHSA-2017:2709",
        "https://access.redhat.com/errata/RHSA-2017:2710",
        "https://access.redhat.com/errata/RHSA-2017:3113",
        "https://access.redhat.com/errata/RHSA-2017:3114",
        "https://access.redhat.com/errata/RHSA-2017:3193",
        "https://access.redhat.com/errata/RHSA-2017:3194",
        "https://access.redhat.com/errata/RHSA-2017:3195",
        "https://access.redhat.com/errata/RHSA-2017:3239",
        "https://access.redhat.com/errata/RHSA-2017:3240",
        "https://httpd.apache.org/security/vulnerabilities_22.html",
        "https://httpd.apache.org/security/vulnerabilities_24.html",
        "https://lists.apache.org/thread.html/0dd69204a6bd643cc4e9ccd008f07a9375525d977c6ebeb07a881afb%40%3Cannounce.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935e2a0a6876dad3c%40%3Ccvs.httpd.apache.org%3E"
    ]
}