CVE-2018-1301

A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very hard if not impossible to trigger in non-debug mode (both log and build level), so it is classified as low risk for common server usage.


We have discovered 778,144 live websites that are affected by CVE-2018-1301.

Run a Free Instant Scan




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains778,144 live websites (31% of Apache install base)
Vulnerable Versions
  • from 2.2 through 2.4.29
Vulnerable Versions Count60 versions ( 49% of all versions)



Details

  • Published - Mar 26, 2018
  • Updated - Sep 16, 2024

Website Distribution by Country

Number of websites using CVE-2018-1301
United States188,196 websites



Taiwan107,242 websites
Germany75,232 websites
France37,594 websites
Japan36,995 websites
Russia34,249 websites
Netherlands29,005 websites
Czech Republic22,876 websites
Italy21,161 websites
Korea, South15,528 websites

Website Distribution by TLD

Number of websites using CVE-2018-1301
.com334,321 websites
.de52,570 websites
.net30,159 websites
.ru29,298 websites
.org28,593 websites
.nl20,935 websites
.cz18,297 websites
.it17,959 websites
.info12,921 websites
.fr11,650 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2018-1301

Top websites that are affected by CVE-2018-1301. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***********.com Canada***
*********.net United States***
***.****.us United States*,***
******************.com United States*,***
*******.**.com United States*,***
*********.******.net United States*,***
****.com United States*,***
********.com United States*,***
****.**.pl Poland*,***
********.in India*,***
See full domain list

FAQ

A total of 778,144 websites have been identified as vulnerable to CVE-2018-1301, based on global website indexing conducted by WebTechSurvey.
The Apache is affected by the CVE-2018-1301 vulnerability.
Apache versions up to and including 2.4.29 are vulnerable to CVE-2018-1301.

References