CVE-2009-1890

The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.


We have discovered 437,247 live websites that are affected by CVE-2009-1890.

Test my site




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains437,247 live websites (13.86% of Apache install base)
Vulnerable Versions
  • from 0 before 2.3.3
Vulnerable Versions Count88 versions ( 59.86% of all versions)



Details

  • Published - Jul 5, 2009
  • Updated - Aug 7, 2024

CVE-2009-1890 usage by Country

United States69,583 websites



Taiwan105,389 websites
Germany40,032 websites
Japan32,075 websites
Russia19,829 websites
France15,766 websites
Czech Republic12,263 websites
GB12,138 websites
Korea, South11,765 websites
Netherlands10,612 websites

CVE-2009-1890 usage by TLD

.com191,308 websites
.de31,346 websites
.net19,242 websites
.ru17,176 websites
.org14,131 websites
.jp10,515 websites
.info10,092 websites
.cz9,997 websites
.nl6,745 websites
.it6,652 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2009-1890

Top websites that are affected by CVE-2009-1890. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***********.com Canada***
*********.******.net United States*,***
****.**.pl Poland*,***
******.com Japan*,***
********.********.de Germany*,***
******.****************.com United States*,***
****.***********.de Germany*,***
**********.com United States*,***
****.**********.com United States*,***
*****.**********.com United States*,***
See full domain list

FAQ

A total of 437,247 websites have been identified as vulnerable to CVE-2009-1890, discovered through global website indexing conducted by WebTechSurvey.
Apache is susceptible to CVE-2009-1890 vulnerability.
Apache versions before 2.3.3 are vulnerable to CVE-2009-1890.
Version 2.3.3 of Apache addresses the CVE-2009-1890 security vulnerability.

References