Apache HTTP Server Resource Management Errors Vulnerability - CVE-2016-1546
The Apache HTTP Server 2.4.17 and 2.4.18 when mod_http2 is enabled does not limit the number of simultaneous stream workers for a single HTTP/2 connection which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows.