CVE-2025-53020: Apache HTTP Server: HTTP/2 DoS by Memory Increase
Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63.
Users are recommended to upgrade to version 2.4.64, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache HTTP Serverto a version that resolves this vulnerability.Fixed in 2.4.64Patch CVE-2025-53020
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53020?
CVE-2025-53020 is classified as a medium severity vulnerability impacting memory management in Apache HTTP Server.
How do I fix CVE-2025-53020?
To fix CVE-2025-53020, upgrade your Apache HTTP Server to version 2.4.64 or later.
Which versions of Apache HTTP Server are affected by CVE-2025-53020?
CVE-2025-53020 affects Apache HTTP Server versions from 2.4.17 up to 2.4.63.
What type of vulnerability is CVE-2025-53020?
CVE-2025-53020 is categorized as a Late Release of Memory after Effective Lifetime vulnerability.
Who is affected by CVE-2025-53020?
Anyone using Apache HTTP Server versions between 2.4.17 and 2.4.63 is potentially affected by CVE-2025-53020.