In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in modproxyhttp2.
Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/49xxx/CVE-2025-49630.json",
"cwe_ids": [
"CWE-617"
],
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "2.4.26"
},
{
"last_affected": "2.4.63"
}
],
"source": "AFFECTED_FIELD"
},
{
"extracted_events": [
{
"introduced": "2.4.26"
}
],
"source": "DESCRIPTION"
}
],
"cna_assigner": "apache"
}