CVE-2025-53020

Apache HTTP Server: HTTP/2 DoS by Memory Increase

Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.


We have discovered 1,121,756 live websites that are affected by CVE-2025-53020.

Run a Free Instant Scan




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains1,121,756 live websites (41% of Apache install base)
Vulnerable Versions
  • from 2.4.17 through 2.4.63
Vulnerable Versions Count39 versions ( 33% of all versions)


Common Weakness Enumeration

CWE-401 Missing Release of Memory after Effective Lifetime



Details

  • Published - Jul 10, 2025
  • Updated - Nov 4, 2025

Credits

  • Gal Bar Nahum (finder)

Website Distribution by Country

Number of websites using CVE-2025-53020
United States306,434 websites



Germany150,909 websites
France72,522 websites
Netherlands59,054 websites
Italy40,161 websites
Russia39,392 websites
Japan36,483 websites
GB34,065 websites
Canada33,895 websites
Czech Republic29,221 websites

Website Distribution by TLD

Number of websites using CVE-2025-53020
.com371,222 websites
.de87,395 websites
.org56,589 websites
.nl44,529 websites
.net43,818 websites
.it36,022 websites
.ru35,460 websites
.fr24,414 websites
.cz24,335 websites
.pl24,131 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-53020

Top websites that are affected by CVE-2025-53020. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com Singapore***
*************.***.****.****.************.net United States***
*********.net United States***
***.****.us United States*,***
***.*********.com Singapore*,***
*****.*******.com Singapore*,***
******.net Sweden*,***
****.*********.net GB*,***
***********.de Germany*,***
***.***********.com United States*,***
See full domain list

FAQ

CVE-2025-53020 is Missing Release of Memory after Effective Lifetime in Apache
A total of 1,121,756 websites have been identified as vulnerable to CVE-2025-53020, based on global website indexing conducted by WebTechSurvey.
The Apache is affected by the CVE-2025-53020 vulnerability.
Apache versions up to and including 2.4.63 are vulnerable to CVE-2025-53020.