CVE-2025-53020 is a late-release-of-memory flaw in Apache HTTP Server HTTP/2 handling. A client can repeatedly submit request header names on an HTTP/2 connection, causing server memory consumption to grow disproportionately because memory resources are not released promptly after their effective lifetime. The issue affects Apache HTTP Server versions 2.4.17 through 2.4.63 and can result in denial of service.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (PoC) exploit for CVE-2025-53020, a memory exhaustion vulnerability in Apache httpd's HTTP/2 implementation. The repository consists of two files: a detailed README.md explaining the vulnerability, attack mechanism, and usage instructions, and poc.py, a Python script that implements the exploit logic. The exploit abuses the HPACK header compression in HTTP/2 by sending requests with repeated long header names, causing the server to allocate excessive memory for each repetition. The script allows customization of header length, number of repetitions, batch size, and delay between batches. It supports both HTTP and HTTPS targets and includes a patch for the h2 library to handle empty header values correctly. The primary attack vector is network-based, targeting HTTP/2 endpoints on Apache httpd servers. The exploit is a functional PoC and does not include weaponized payloads beyond denial of service. No hardcoded IPs or domains are present; endpoints are user-supplied via command-line arguments. The repository is intended for authorized security testing and research.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A denial-of-service vulnerability in Apache HTTP Server's mod_http2 module that can cause memory increase during HTTP/2 handling.
A high-severity Apache HTTP Server HTTP/2 memory-exhaustion vulnerability caused by late release of memory after its effective lifetime, enabling substantial allocation amplification.
A denial-of-service vulnerability in Apache HTTP Server HTTP/2 handling that causes memory increase.
An Apache HTTP Server HTTP/2 denial-of-service vulnerability caused by memory increase.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.