Looking for the vulnerability index of Invicti's legacy products?
Apache HTTP Server Reachable Assertion Vulnerability (CVE-2025-49630) - Vulnerability Database

Apache HTTP Server Reachable Assertion Vulnerability (CVE-2025-49630)

Description

In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".

References