#VU64085 Input validation error in Apache HTTP Server - CVE-2022-29404
Published: June 8, 2022 / Updated: April 21, 2023
Apache HTTP Server
Apache Foundation
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when processing HTTP requests to a lua script that calls r:parsebody(0). A remote attacker can send a very large HTTP request to the affected web server and perform a denial of service (DoS) attack.