← back
CVE-2022-22721CWE-190

core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody

15Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 42%
exploitation probability
42%top 1% of all CVEs
observed exploitation
nono source reports it
If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.