ECHO-f759-d499-ad5c

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-f759-d499-ad5c.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-f759-d499-ad5c
Upstream
Withdrawn
2026-07-13T15:45:01Z
Published
2026-05-28T15:28:36Z
Modified
2026-07-13T16:30:03Z
Summary
DoS (bandwidth consumption) via a Range header specifying multiple copies of the same fragment over a TCP connection with a large window size. The severity is explicitly disputed by third parties (NVD carries the "disputed" tag) because the large TCP window size the attack relies on is not normally supported or configured by the server, and the same effect is achievable by simply downloading the file. Red Hat states it "does not consider this issue to be a security vulnerability". Debian classifies it as an unimportant issue. No code change required in the shipped 2.4.68 build. https://security-tracker.debian.org/tracker/CVE-2007-0086
Details
References

Affected packages

Echo / apache2

Package

Name
apache2
Purl
pkg:deb/echo/apache2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.4.68-1~deb13u1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-f759-d499-ad5c.json"