httpd: possible temporary DoS (CPU consumption) in mod_deflate
Published Jul 10, 2009
7.1
HIGHCVSS 2.0
EPSS 17.11%
Description
The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).
Affected products
No data.
Configuration 1
- ≥ 2.0.35 · < 2.0.64
- ≥ 2.2.0 · < 2.2.12
Configuration 2
- 4.0
- 5.0
- 6.0
Configuration 3
- 11
Configuration 4
- 6.06
- 8.04
- 8.10
- 9.04
Configuration 5
- 5.0
- 5.3
- 5.0
- 5.3
- 5.0
No data.
JBEWS 1.0 for RHEL 4
httpd22-0:2.2.10-23.1.ep5.el4
Fixed · RHSA-2009:1160
Red Hat Certificate System 7.3
ant-0:1.6.5-1jpp_1rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
avalon-logkit-0:1.2-2jpp_4rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
axis-0:1.2.1-1jpp_3rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
classpathx-jaf-0:1.0-2jpp_6rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
classpathx-mail-0:1.1.1-2jpp_8rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
geronimo-specs-0:1.0-0.M4.1jpp_10rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
jakarta-commons-modeler-0:2.0-3jpp_2rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
log4j-0:1.2.12-1jpp_1rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
mx4j-1:3.0.1-1jpp_4rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
pcsc-lite-0:1.3.3-3.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-ca-0:7.3.0-20.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-java-tools-0:7.3.0-10.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-kra-0:7.3.0-14.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-manage-0:7.3.0-19.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-native-tools-0:7.3.0-6.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-ocsp-0:7.3.0-13.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-tks-0:7.3.0-13.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
tomcat5-0:5.5.23-0jpp_4rh.16
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
xerces-j2-0:2.7.1-1jpp_1rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
xml-commons-0:1.3.02-2jpp_1rh
Fixed · RHSA-2010:0602
Red Hat Enterprise Linux 3
httpd-0:2.0.46-75.ent
Fixed · RHSA-2009:1205
Red Hat Enterprise Linux 4
httpd-0:2.0.52-41.ent.6
Fixed · RHSA-2009:1580
Red Hat Enterprise Linux 5
httpd-0:2.2.3-22.el5_3.2
Fixed · RHSA-2009:1148
Red Hat JBoss Enterprise Web Server 1 for RHEL 5
httpd-0:2.2.10-10.ep5.el5
Fixed · RHSA-2009:1155
| Product | Package | State | Advisory |
|---|---|---|---|
| JBEWS 1.0 for RHEL 4 | httpd22-0:2.2.10-23.1.ep5.el4 | Fixed | RHSA-2009:1160 |
| Red Hat Certificate System 7.3 | ant-0:1.6.5-1jpp_1rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | avalon-logkit-0:1.2-2jpp_4rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | axis-0:1.2.1-1jpp_3rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | classpathx-jaf-0:1.0-2jpp_6rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | classpathx-mail-0:1.1.1-2jpp_8rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | geronimo-specs-0:1.0-0.M4.1jpp_10rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | jakarta-commons-modeler-0:2.0-3jpp_2rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | log4j-0:1.2.12-1jpp_1rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | mx4j-1:3.0.1-1jpp_4rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | pcsc-lite-0:1.3.3-3.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-ca-0:7.3.0-20.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-java-tools-0:7.3.0-10.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-kra-0:7.3.0-14.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-manage-0:7.3.0-19.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-native-tools-0:7.3.0-6.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-ocsp-0:7.3.0-13.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-tks-0:7.3.0-13.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | tomcat5-0:5.5.23-0jpp_4rh.16 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | xerces-j2-0:2.7.1-1jpp_1rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | xml-commons-0:1.3.02-2jpp_1rh | Fixed | RHSA-2010:0602 |
| Red Hat Enterprise Linux 3 | httpd-0:2.0.46-75.ent | Fixed | RHSA-2009:1205 |
| Red Hat Enterprise Linux 4 | httpd-0:2.0.52-41.ent.6 | Fixed | RHSA-2009:1580 |
| Red Hat Enterprise Linux 5 | httpd-0:2.2.3-22.el5_3.2 | Fixed | RHSA-2009:1148 |
| Red Hat JBoss Enterprise Web Server 1 for RHEL 5 | httpd-0:2.2.10-10.ep5.el5 | Fixed | RHSA-2009:1155 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2022-2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (44 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 17.11% (0.17111) | 97.00th | v5 (v2026.06.15) |
| Jun 15, 2026 | 17.11% (0.17111) | 96.68th | v5 (v2026.06.15) |
| Jun 8, 2026 | 20.97% (0.20968) | 95.76th | v4 (v2025.03.14) |
| Mar 4, 2026 | 18.85% (0.18846) | 95.17th | v4 (v2025.03.14) |
| Mar 1, 2026 | 9.32% (0.09323) | 92.65th | v4 (v2025.03.14) |
| Feb 4, 2026 | 18.85% (0.18846) | 95.12th | v4 (v2025.03.14) |
| Feb 1, 2026 | 9.32% (0.09323) | 92.58th | v4 (v2025.03.14) |
| Jan 4, 2026 | 18.81% (0.18812) | 95.07th | v4 (v2025.03.14) |
| Jan 1, 2026 | 9.30% (0.09303) | 92.54th | v4 (v2025.03.14) |
| Dec 28, 2025 | 18.81% (0.18812) | 95.08th | v4 (v2025.03.14) |
| Dec 27, 2025 | 14.81% (0.14811) | 94.32th | v4 (v2025.03.14) |
| Dec 4, 2025 | 18.81% (0.18812) | 95.04th | v4 (v2025.03.14) |
| Dec 1, 2025 | 9.30% (0.09303) | 92.47th | v4 (v2025.03.14) |
| Nov 4, 2025 | 18.81% (0.18812) | 95.02th | v4 (v2025.03.14) |
| Nov 1, 2025 | 9.30% (0.09303) | 92.43th | v4 (v2025.03.14) |
| Oct 28, 2025 | 20.93% (0.20931) | 95.38th | v4 (v2025.03.14) |
| Oct 27, 2025 | 14.81% (0.14811) | 94.24th | v4 (v2025.03.14) |
| Oct 4, 2025 | 20.93% (0.20931) | 95.42th | v4 (v2025.03.14) |
| Oct 1, 2025 | 10.53% (0.10525) | 93.01th | v4 (v2025.03.14) |
| Sep 4, 2025 | 14.81% (0.14811) | 94.28th | v4 (v2025.03.14) |
| Sep 1, 2025 | 8.03% (0.08029) | 91.83th | v4 (v2025.03.14) |
| Aug 4, 2025 | 14.81% (0.14811) | 94.23th | v4 (v2025.03.14) |
| Aug 1, 2025 | 8.03% (0.08029) | 91.80th | v4 (v2025.03.14) |
| Jul 30, 2025 | 14.81% (0.14811) | 94.22th | v4 (v2025.03.14) |
| Jul 4, 2025 | 20.93% (0.20931) | 95.35th | v4 (v2025.03.14) |
| Jul 1, 2025 | 10.53% (0.10525) | 92.94th | v4 (v2025.03.14) |
| Jun 4, 2025 | 20.93% (0.20931) | 95.30th | v4 (v2025.03.14) |
| Jun 1, 2025 | 10.53% (0.10525) | 92.88th | v4 (v2025.03.14) |
| May 4, 2025 | 20.93% (0.20931) | 95.25th | v4 (v2025.03.14) |
| May 1, 2025 | 10.53% (0.10525) | 92.86th | v4 (v2025.03.14) |
| Mar 30, 2025 | 20.93% (0.20931) | 95.14th | v4 (v2025.03.14) |
| Mar 29, 2025 | 23.26% (0.23263) | 93.46th | v4 (v2025.03.14) |
| Mar 17, 2025 | 20.93% (0.20931) | 95.16th | v4 (v2025.03.14) |
| Dec 17, 2024 | 15.77% (0.15772) | 95.90th | v3 (v2023.03.01) |
| Jun 16, 2024 | 0.70% (0.00698) | 80.33th | v3 (v2023.03.01) |
| Mar 30, 2024 | 0.49% (0.00492) | 75.75th | v3 (v2023.03.01) |
| Feb 18, 2024 | 0.38% (0.00382) | 72.32th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.27% (0.00269) | 66.86th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.27% (0.00269) | 62.62th | v3 (v2023.03.01) |
| Mar 6, 2023 | 7.34% (0.07344) | 92.59th | v2 (v2022.01.01) |
| Jul 18, 2022 | 7.34% (0.07344) | 92.17th | v2 (v2022.01.01) |
| Jul 17, 2022 | 3.93% (0.03932) | 85.06th | v2 (v2022.01.01) |
| Apr 1, 2022 | 7.34% (0.07344) | 91.87th | v2 (v2022.01.01) |
| Feb 4, 2022 | 7.34% (0.07344) | 80.64th | v2 (v2022.01.01) |
References (58)
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534712 x_refsource_MISCExploit
- http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html vendor-advisoryx_refsource_APPLEBroken LinkMailing List
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00006.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://marc.info/?l=apache-httpd-dev&m=124621326524824&w=2 mailing-listx_refsource_MLISTExploitIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=apache-httpd-dev&m=124661528519546&w=2 mailing-listx_refsource_MLISTIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=129190899612998&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=130497311408250&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://osvdb.org/55782 vdb-entryx_refsource_OSVDBBroken Link
- http://secunia.com/advisories/35721 third-party-advisoryx_refsource_SECUNIANot ApplicableVendor Advisory
- http://secunia.com/advisories/35781 third-party-advisoryx_refsource_SECUNIANot ApplicableVendor Advisory
- http://secunia.com/advisories/35793 third-party-advisoryx_refsource_SECUNIANot ApplicableVendor Advisory
- http://secunia.com/advisories/35865 third-party-advisoryx_refsource_SECUNIANot ApplicableVendor Advisory
- http://secunia.com/advisories/37152 third-party-advisoryx_refsource_SECUNIANot ApplicableVendor Advisory
- http://secunia.com/advisories/37221 third-party-advisoryx_refsource_SECUNIANot ApplicableVendor Advisory
- http://security.gentoo.org/glsa/glsa-200907-04.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://support.apple.com/kb/HT3937 x_refsource_CONFIRMBroken Link
- http://wiki.rpath.com/Advisories:rPSA-2009-0142 x_refsource_CONFIRMBroken Link
- http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0142 x_refsource_CONFIRMBroken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK91361 vendor-advisoryx_refsource_AIXAPARThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK99480 vendor-advisoryx_refsource_AIXAPARThird Party Advisory
- http://www.debian.org/security/2009/dsa-1834 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:149 vendor-advisoryx_refsource_MANDRIVABroken LinkPatch
- http://www.redhat.com/support/errata/RHSA-2009-1156.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.securityfocus.com/archive/1/507857/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1022529 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-802-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.vupen.com/english/advisories/2009/1841 vdb-entryx_refsource_VUPENPermissions RequiredVendor Advisory
- http://www.vupen.com/english/advisories/2009/3184 vdb-entryx_refsource_VUPENPermissions RequiredVendor Advisory
- https://access.redhat.com/security/cve/CVE-2009-1891 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=509125 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2009-1891
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12361 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8632 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9248 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2009-1148.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2009-1891
- https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01363.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
Change history (0)
No recorded changes yet.