peter bassill · operator
$ cve CVE-2022-22721 JSON

CVE-2022-22721

9.1
CRITICAL · CVSS 3.1 · EPSS 41.7% (pctl 99)

Patch early

EPSS 41.7% — above the 10% action threshold.

Description

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS41.71% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-190
On CISA KEVno
Public exploitnone known
Published2022-03-14
Last modified2026-06-17

Affected (8)

VendorProduct
apachehttp server
applemac os x
applemacos
debiandebian linux
fedoraprojectfedora
oracleenterprise manager ops center
oraclehttp server
oraclezfs storage appliance kit

References

→ the Explorer  ·  watch your stack  ·  NVD