CVE-2022-28615

CVE-2022-28615: Read beyond bounds in ap_strcmp_match()

Vendor Apache Software Foundation
Product Apache HTTP Server
Weakness CWE-190
Published June 8, 2022
Last update December 18, 2025

CVSS base score

What the vulnerability does

01Description

Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua scripts that use ap_strcmp_match() may hypothetically be affected.

Key dates

02Disclosure timeline

June 8, 2022 CVE published
December 18, 2025 Record updated