Description
The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor.
Remediation
References
Related Vulnerabilities
Moodle URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2019-14830)
Liferay Portal Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2025-43827)
Next.js Uncontrolled Resource Consumption Vulnerability (CVE-2025-59471)
WordPress 4.0.x Multiple Vulnerabilities (4.0 - 4.0.24)
Plone CMS Improper Input Validation Vulnerability (CVE-2013-4192)