CVE-2022-22721

core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.


We have discovered 978,452 live websites that are affected by CVE-2022-22721.

Run a Free Instant Scan




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains978,452 live websites (37% of Apache install base)
Vulnerable Versions
  • from 2.4 through 2.4.52
Vulnerable Versions Count44 versions ( 37% of all versions)


Common Weakness Enumeration

CWE-190 Integer Overflow or Wraparound



Details

  • Published - Mar 14, 2022
  • Updated - Aug 3, 2024

Credits

  • Anonymous working with Trend Micro Zero Day Initiative

Website Distribution by Country

Number of websites using CVE-2022-22721
United States295,614 websites



Germany106,373 websites
France55,617 websites
Russia41,755 websites
Japan40,800 websites
Italy34,289 websites
Singapore33,411 websites
Netherlands30,018 websites
GB26,895 websites
Canada25,344 websites

Website Distribution by TLD

Number of websites using CVE-2022-22721
.com364,928 websites
.de62,599 websites
.org46,002 websites
.net38,665 websites
.ru36,688 websites
.it30,412 websites
.nl22,364 websites
.cz20,841 websites
.pl20,371 websites
.jp18,112 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-22721

Top websites that are affected by CVE-2022-22721. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com Singapore***
*************.***.****.****.************.net United States***
*********.net United States***
***.****.us United States*,***
***.*********.com Singapore*,***
*****.*******.com Singapore*,***
******************.com United States*,***
****.*********.net GB*,***
****.com United States*,***
********.com United States*,***
See full domain list

FAQ

CVE-2022-22721 is Integer Overflow or Wraparound in Apache
A total of 978,452 websites have been identified as vulnerable to CVE-2022-22721, based on global website indexing conducted by WebTechSurvey.
The Apache is affected by the CVE-2022-22721 vulnerability.
Apache versions up to and including 2.4.52 are vulnerable to CVE-2022-22721.

References