VDB

ALPINE-CVE-2022-22721

ALPINE-CVE-2022-22721 PUBLISHED CVSS 9.100000381469727 CRITICAL

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

Risk Scores

CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Affected Products

VendorProductVersions
Alpine:v3.19apache20, 2.2.16-r0, 2.2.16-r1
Alpine:v3.16apache22.2.17-r0, 2.2.17-r1, 2.2.17-r2
Alpine:v3.15apache22.4.12-r4, 0, 0
Alpine:v3.14apache22.4.12-r3, 2.4.17-r0, 2.4.17-r2
Alpine:v3.24apache20, 0
Alpine:v3.17apache22.2.16-r1, 2.2.16-r2, 2.2.16-r3
Alpine:v3.23apache22.4.10-r0, 0, 2.2.16-r0
Alpine:v3.13apache22.2.17-r1, 0, 0
Alpine:v3.18apache22.4.23-r5, 2.4.23-r4, 2.4.23-r3
Alpine:v3.20apache22.2.16-r1, 0, 0
Alpine:v3.22apache22.4.17-r5, 2.4.17-r4, 2.2.16-r3
Alpine:v3.21apache22.2.16-r0, 0, 2.4.17-r4
Alpine:v3.12apache20, 0, 2.4.9-r1

Timeline

  • Mar 14, 2022 CVE Published
  • Jun 15, 2026 CVE Updated
  • Aug 8, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›