CVE-2024-38476
published 2024-07-01CVE-2024-38476: Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend…
PriorityP267critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
41.61%
98.5th percentile
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.4.0 < 2.4.60 | 2.4.60 |
| apache_software_foundation | apache_http_server | 2.4.0 – 2.4.59 | — |
| apple | macos_sequoia | — | — |
| debian | apache2 | < apache2 2.4.61-1~deb12u1 (bookworm) | apache2 2.4.61-1~deb12u1 (bookworm) |
| netapp | clustered_data_ontap | — | — |
| ubuntu | apache2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target versions: Apache HTTP Server 2.4.59 and earlier are vulnerable; the attack vector is malicious or exploitable response headers from backend applications, enabling information disclosure, SSRF, or local script execution. ↗
- →The vulnerability is exploitable remotely over HTTP; detection should focus on anomalous or crafted response headers returned by backend/proxy applications to the Apache HTTP Server core. ↗
- →Monitor for SSRF-indicative outbound requests originating from the Apache HTTP Server process, which may indicate exploitation via a malicious backend response header. ↗
- →This flaw can only be triggered through backend applications; detection should include inspection of proxy/backend response headers for unexpected or injected header values that could influence Apache core behavior. ↗
- ·Red Hat Enterprise Linux 6 is not affected because the vulnerable code was introduced in a newer version of httpd; do not prioritize patching on RHEL 6 systems. ↗
- ·The fix for CVE-2024-38476 (introduced in Apache HTTP Server 2.4.60) itself caused a regression (CVE-2024-39884) that can lead to source code disclosure via legacy AddType/content-type handler configuration; upgrading to 2.4.61 is required to fully remediate both issues. ↗
- ·No practical mitigation short of patching has been identified by Red Hat; update the affected package as soon as possible. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache HTTP Server regression
vendor_ubuntu·2026-05-29·CVSS 7.3
CVE-2023-38709 [HIGH] Apache HTTP Server regression
Title: Apache HTTP Server regression
Summary: USN-8338-1 introduced a regression in Apache HTTP Server
USN-8338-1 fixed vulnerabilities in Apache HTTP Server. The update
introduced a regression that prevented mod_http2 from loading on Ubuntu
18.04 LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Apache HTTP Server incorrectly handled certain
response headers. An attacker could possibly use this issue to perform
HTTP response splitting attacks. This issue only affected Ubuntu 14.04
LTS. (CVE-2023-38709)
Will Dormann and David Warren discovered that Apache HTTP Server's HTTP/2
implementation did not properly reclaim memory when streams were reset by
clients. A remote attacker could possibly use this issue to cause
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-05-28·CVSS 7.3
CVE-2023-38709 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
It was discovered that Apache HTTP Server incorrectly handled certain
response headers. An attacker could possibly use this issue to perform
HTTP response splitting attacks. This issue only affected Ubuntu 14.04
LTS. (CVE-2023-38709)
Will Dormann and David Warren discovered that Apache HTTP Server's HTTP/2
implementation did not properly reclaim memory when streams were reset by
clients. A remote attacker could possibly use this issue to cause Apache
HTTP Server to consume resources, leading to a denial of service. This
issue only affected Ubuntu 18.04 LTS. (CVE-2023-45802)
Keran Mu and Jianjun Chen discovered that Apache HTTP Server incorrectly
handled certain response headers.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Core (Apache HTTP Server) — CVE-2024-38476
vendor_oracle·2025-04-15·CVSS 9.8
CVE-2024-38476 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Core (Apache HTTP Server) — CVE-2024-38476
Oracle Oracle Fusion Middleware Risk Matrix: Core (Apache HTTP Server) vulnerability
CVE: CVE-2024-38476
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
Apple
CVE-2024-38476: macOS Sequoia 15.1
vendor_apple·2024-10-28·CVSS 9.8
CVE-2024-38476 [CRITICAL] CVE-2024-38476: macOS Sequoia 15.1
Apple Security Update: About the security content of macOS Sequoia 15.1
Product: macOS Sequoia
Version: 15.1
CVE: CVE-2024-38476
Component: CVE-2024-38476
Oracle
Oracle Oracle Secure Backup Risk Matrix: Oracle Secure Backup (Apache HTTP Server) — CVE-2024-38476
vendor_oracle·2024-10-15·CVSS 7.5
CVE-2024-38476 [CRITICAL] Oracle Oracle Secure Backup Risk Matrix: Oracle Secure Backup (Apache HTTP Server) — CVE-2024-38476
Oracle Oracle Secure Backup Risk Matrix: Oracle Secure Backup (Apache HTTP Server) vulnerability
CVE: CVE-2024-38476
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2024-09-18·CVSS 9.8
CVE-2024-38475 [CRITICAL] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
USN-6885-1 fixed several vulnerabilities in Apache. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
Orange Tsai discovered that the Apache HTTP Server mod_rewrite module
incorrectly handled certain substitutions. A remote attacker could
possibly use this issue to execute scripts in directories not directly
reachable by any URL, or cause a denial of service. Some environments
may require using the new UnsafeAllow3F flag to handle unsafe
substitutions. (CVE-2024-38474, CVE-2024-38475)
Orange Tsai discovered that the Apache HTTP Server incorrectly handled
certain response headers. A remote attacker could possibly
Ubuntu
Apache HTTP Server regression
vendor_ubuntu·2024-07-11·CVSS 5.4
[MEDIUM] Apache HTTP Server regression
Title: Apache HTTP Server regression
Summary: USN-6885-1 introduced a regression in Apache HTTP Server.
USN-6885-1 fixed vulnerabilities in Apache HTTP Server. One of the security
fixes introduced a regression when proxying requests to a HTTP/2 server.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Marc Stern discovered that the Apache HTTP Server incorrectly handled
serving WebSocket protocol upgrades over HTTP/2 connections. A remote
attacker could possibly use this issue to cause the server to crash,
resulting in a denial of service. (CVE-2024-36387)
Orange Tsai discovered that the Apache HTTP Server mod_proxy module
incorrectly sent certain request URLs with incorrect encodings to backends.
A remote attacker could possibly use this i
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2024-07-08·CVSS 5.4
CVE-2024-38475 [MEDIUM] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
Marc Stern discovered that the Apache HTTP Server incorrectly handled
serving WebSocket protocol upgrades over HTTP/2 connections. A remote
attacker could possibly use this issue to cause the server to crash,
resulting in a denial of service. (CVE-2024-36387)
Orange Tsai discovered that the Apache HTTP Server mod_proxy module
incorrectly sent certain request URLs with incorrect encodings to backends.
A remote attacker could possibly use this issue to bypass authentication.
(CVE-2024-38473)
Orange Tsai discovered that the Apache HTTP Server mod_rewrite module
incorrectly handled certain substitutions. A remote attacker could possibly
use this issue to execute scripts in directori
Red Hat
httpd: source code disclosure with handlers configured via AddType
vendor_redhat·2024-07-04·CVSS 9.8
CVE-2024-39884 [CRITICAL] CWE-200 httpd: source code disclosure with handlers configured via AddType
httpd: source code disclosure with handlers configured via AddType
A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted.
Users are recommended to upgrade to version 2.4.61, which fixes this issue.
A flaw was found in httpd. The fix for CVE-2024-38476 ignores some uses of the legacy content-type based configuration of handlers. "AddType" and similar configurations, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts m
Red Hat
httpd: Security issues via backend applications whose response headers are malicious or exploitable
vendor_redhat·2024-07-01·CVSS 9.8
CVE-2024-38476 [CRITICAL] CWE-829 httpd: Security issues via backend applications whose response headers are malicious or exploitable
httpd: Security issues via backend applications whose response headers are malicious or exploitable
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
A flaw was found in httpd. Backend applications whose response headers are malicious or exploitable may allow information disclosure, server-side request forgery (SSRF) or local script execution.
Statement: This flaw can only be exploited by backend applications via malicious or exploitable response headers. For this reason, this flaw was rated with an important and not critical severity.
Red Hat Enterpr
Debian
CVE-2024-38476: apache2 - Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to...
vendor_debian·2024·CVSS 9.8
CVE-2024-38476 [CRITICAL] CVE-2024-38476: apache2 - Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to...
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Scope: local
bookworm: resolved (fixed in 2.4.61-1~deb12u1)
bullseye: resolved (fixed in 2.4.61-1~deb11u1)
forky: resolved (fixed in 2.4.60-1)
sid: resolved (fixed in 2.4.60-1)
trixie: resolved (fixed in 2.4.60-1)
OSV
apache2 vulnerabilities
osv·2024-09-18·CVSS 9.8
[CRITICAL] apache2 vulnerabilities
apache2 vulnerabilities
USN-6885-1 fixed several vulnerabilities in Apache. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
Orange Tsai discovered that the Apache HTTP Server mod_rewrite module
incorrectly handled certain substitutions. A remote attacker could
possibly use this issue to execute scripts in directories not directly
reachable by any URL, or cause a denial of service. Some environments
may require using the new UnsafeAllow3F flag to handle unsafe
substitutions. (CVE-2024-38474, CVE-2024-38475)
Orange Tsai discovered that the Apache HTTP Server incorrectly handled
certain response headers. A remote attacker could possibly use this issue
to obtain sensitive information, execute local scripts, or perform SSRF
OSV
apache2 regression
osv·2024-07-11·CVSS 5.4
[MEDIUM] apache2 regression
apache2 regression
USN-6885-1 fixed vulnerabilities in Apache HTTP Server. One of the security
fixes introduced a regression when proxying requests to a HTTP/2 server.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Marc Stern discovered that the Apache HTTP Server incorrectly handled
serving WebSocket protocol upgrades over HTTP/2 connections. A remote
attacker could possibly use this issue to cause the server to crash,
resulting in a denial of service. (CVE-2024-36387)
Orange Tsai discovered that the Apache HTTP Server mod_proxy module
incorrectly sent certain request URLs with incorrect encodings to backends.
A remote attacker could possibly use this issue to bypass authentication.
(CVE-2024-38473)
Orange Tsai discovered that the Apach
OSV
apache2 vulnerabilities
osv·2024-07-08·CVSS 5.4
CVE-2024-36387 [MEDIUM] apache2 vulnerabilities
apache2 vulnerabilities
Marc Stern discovered that the Apache HTTP Server incorrectly handled
serving WebSocket protocol upgrades over HTTP/2 connections. A remote
attacker could possibly use this issue to cause the server to crash,
resulting in a denial of service. (CVE-2024-36387)
Orange Tsai discovered that the Apache HTTP Server mod_proxy module
incorrectly sent certain request URLs with incorrect encodings to backends.
A remote attacker could possibly use this issue to bypass authentication.
(CVE-2024-38473)
Orange Tsai discovered that the Apache HTTP Server mod_rewrite module
incorrectly handled certain substitutions. A remote attacker could possibly
use this issue to execute scripts in directories not directly reachable
by any URL, or cause a denial of service. Some environments
OSV
CVE-2024-38476: Vulnerability in core of Apache HTTP Server 2
osv·2024-07-01·CVSS 9.8
CVE-2024-38476 [CRITICAL] CVE-2024-38476: Vulnerability in core of Apache HTTP Server 2
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
GHSA
GHSA-fpq9-w5cw-5hf8: Vulnerability in core of Apache HTTP Server 2
ghsa_unreviewed·2024-07-01
CVE-2024-38476 [CRITICAL] CWE-829 GHSA-fpq9-w5cw-5hf8: Vulnerability in core of Apache HTTP Server 2
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
OSV
CVE-2024-38476: Vulnerability in core of Apache HTTP Server 2
osv·2024-07-01·CVSS 9.8
CVE-2024-38476 [CRITICAL] CVE-2024-38476: Vulnerability in core of Apache HTTP Server 2
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
No detection rules found.
No public exploits indexed.
Qualys
Oracle Critical Patch Update, April 2025 Security Update Review
blogs_qualys·2025-04-16
Oracle Critical Patch Update, April 2025 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Oracle released its first quarterly edition of this year’s Critical Patch Update. The update received patches for 378 s ecurity vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 103, constituting about 27% of the total patches released. Oracle MySQL and Oracle Communications Applications followed, with 43 and 42 security patches.
300 of the 378 security patches provided by the April Critical Patch Update (about 79%) are for non-Ora
Qualys
Oracle Critical Patch Update, April 2025 Security Update Review | Qualys
blogs_qualys·2025-04-16
Oracle Critical Patch Update, April 2025 Security Update Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
Oracle released its first quarterly edition of this year’s Critical Patch Update. The update received patches for 378 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 103, constituting about 27% of the total patches released. Oracle MySQL and Oracle Communications Applications followed, with 43 and 42 security patches.
300 of the 378 security patches provided by the April Critical Patch Update (about 79%) are for non
arXiv
Plug. Play. Persist. Inside a Ready-to-Go Havoc C2 Infrastructure
arxiv_fulltext·2025-06-30·CVSS 9.8
[CRITICAL] Plug. Play. Persist. Inside a Ready-to-Go Havoc C2 Infrastructure
titlepage
*1cm
Plug. Play. Persist. Inside a Ready-to-Go Havoc C2 Infrastructure \ 1cm]
Alessio Di Santo ([email protected])
Università degli Studi dell’Aquila, L’Aquila, Abruzzo, Italy
Date: July 1,2025
!60 "Non videmus ea quae mox futura sunt" \ 0.5cm]
!60(We do not see the things that will soon be) — Marcus Tullius Cicero
titlepage
## Executive Summary
This analysis focuses on a single Azure-hosted Virtual Machine at 52.230.23[.]114 that the adversary converted into an all-in-one delivery, staging and Command-and-Control node. The host advertises an out-of-date Apache 2.4.52 instance whose open directory exposes phishing lures, PowerShell loaders, Reflective Shell-Code, compiled Havoc Demon implants and a toolbox of lateral-movement binaries; the same server als
HackerOne
important: Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect (CVE-2024-38476)
hackerone·2024-07-13·CVSS 9.8
CVE-2024-38476 [CRITICAL] important: Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect (CVE-2024-38476)
important: Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect (CVE-2024-38476)
I reported this vulnerability through the official Apache HTTP Server security email on April 1, 2024, and received a fix along with a CVE number on July 1, 2024. You can check detailed information from there:
> https://httpd.apache.org/security/vulnerabilities_24.html
## Impact
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.
Note: Some legacy uses of the 'AddType' directive to connect a request to a handler must be ported to 'SetHandler' after this fix.
Users are recommended
https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://security.netapp.com/advisory/ntap-20240712-0001/http://seclists.org/fulldisclosure/2024/Oct/11http://www.openwall.com/lists/oss-security/2024/07/01/9https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://security.netapp.com/advisory/ntap-20240712-0001/
2024-07-01
Published