### [CVE-2018-17189](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17189) ![](https://img.shields.io/static/v1?label=Product&message=Apache%20HTTP%20Server&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=mod_http2%2C%20DoS%20via%20slow%20request%20bodies&color=brighgreen) ### Description In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connections. ### POC #### Reference - https://www.oracle.com/security-alerts/cpujan2020.html - https://www.oracle.com/security-alerts/cpujan2020.html #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/SzeKiatTan/nlp-cve-vendor-classification - https://github.com/SzeKiatTan/nlp-cve-vendor-classification-gpt2 - https://github.com/austin-lai/External-Penetration-Testing-Holo-Corporate-Network-TryHackMe-Holo-Network - https://github.com/bioly230/THM_Skynet - https://github.com/vshaliii/Basic-Pentesting-2-Vulnhub-Walkthrough - https://github.com/vshaliii/DC-2-Vulnhub-Walkthrough - https://github.com/vshaliii/DC-3-Vulnhub-Walkthrough - https://github.com/vshaliii/Funbox2-rookie