{"id":"ECHO-f759-d499-ad5c","upstream":["CVE-2007-0086"],"severity":[],"modified":"2026-07-13T15:45:01.813Z","affected":[{"package":{"ecosystem":"Echo","name":"apache2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.68-1~deb13u1"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2007-0086"}],"withdrawn":"2026-07-13T15:45:01.813Z","summary":"DoS (bandwidth consumption) via a Range header specifying multiple\ncopies of the same fragment over a TCP connection with a large window\nsize. The severity is explicitly disputed by third parties (NVD carries\nthe \"disputed\" tag) because the large TCP window size the attack relies\non is not normally supported or configured by the server, and the same\neffect is achievable by simply downloading the file. Red Hat states it\n\"does not consider this issue to be a security vulnerability\". Debian\nclassifies it as an unimportant issue. No code change required in the\nshipped 2.4.68 build.\nhttps://security-tracker.debian.org/tracker/CVE-2007-0086\n"}