Apache HTTP Server

38 known vulnerabilities in Apache HTTP Server, 10 critical, 5 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2024-38475 CVSS 9.1 critical · actively exploited Apache HTTP Server Improper Escaping of Output Vulnerability
  • CVE-2021-42013 CVSS 9.8 critical · actively exploited Apache HTTP Server Path Traversal Vulnerability
  • CVE-2021-41773 CVSS 9.8 critical · actively exploited Apache HTTP Server Path Traversal Vulnerability
  • CVE-2021-40438 CVSS 9.0 critical · actively exploited Apache HTTP Server-Side Request Forgery (SSRF)
  • CVE-2019-0211 CVSS 7.8 high · actively exploited Apache HTTP Server Privilege Escalation Vulnerability

Latest vulnerabilities

  • CVE-2026-93546 CVSS 8.8 high Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash…
  • CVE-2026-79768 CVSS 5.3 medium Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute…
  • CVE-2026-73637 CVSS 7.3 high Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an…
  • CVE-2026-73636 CVSS 8.1 high Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows…
  • CVE-2026-63718 CVSS 7.5 high Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server…
  • CVE-2026-63686 CVSS 7.5 high A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an…
  • CVE-2026-63292 CVSS 7.5 high Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a…
  • CVE-2026-63045 CVSS 7.5 high Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all…
  • CVE-2026-59797 CVSS 9.8 critical Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue…
  • CVE-2026-59685 CVSS 7.5 high Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This…
  • CVE-2026-58415 CVSS 5.3 medium Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all…
  • CVE-2026-57941 CVSS 9.8 critical Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP…
  • CVE-2026-56449 CVSS 7.5 high Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP…
  • CVE-2026-56154 CVSS 9.8 critical Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP…
  • CVE-2026-56153 CVSS 7.5 high Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through…
  • CVE-2026-48005 CVSS 7.5 high Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an…
  • CVE-2026-47360 CVSS 7.5 high Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module. When…
  • CVE-2026-46729 CVSS 7.5 high NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP…
  • CVE-2026-42528 CVSS 4.3 medium A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash…
  • CVE-2026-42356 CVSS 3.7 low Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be…
  • CVE-2026-49975 CVSS 7.5 high Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP…
  • CVE-2026-48913 CVSS 7.3 high Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache…
  • CVE-2026-44631 CVSS 9.8 critical Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP…
  • CVE-2026-44186 CVSS 7.3 high Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker…
  • CVE-2026-44185 CVSS 7.3 high Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects…
  • CVE-2026-44119 CVSS 5.5 medium Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the…
  • CVE-2026-43951 CVSS 6.5 medium Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects…
  • CVE-2026-42536 CVSS 7.5 high Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects…
  • CVE-2026-42535 CVSS 9.1 critical A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV…
  • CVE-2026-34356 CVSS 7.5 high Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue…