Apache Http Server vulnerabilities
323 known vulnerabilities affecting apache/http_server.
Total CVEs
323
CISA KEV
5
actively exploited
Public exploits
70
Exploited in wild
22
Severity breakdown
CRITICAL38HIGH107MEDIUM165LOW13
Vulnerabilities
Page 10 of 17
CVE-2009-1890P3HIGHCVSS 7.1≥ 2.2.0, < 2.2.122009-07-05
CVE-2009-1890 [HIGH] CWE-400 CVE-2009-1890: The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server
The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.
nvd
CVE-2017-12171P3MEDIUMCVSS 6.5v2.2.15-602018-07-26
CVE-2017-12171 [MEDIUM] CWE-284 CVE-2017-12171: A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comme
A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines to be parsed incorrectly. A web administrator could unintentionally allow any client to access a restricted HTTP resource.
nvd
CVE-2025-65082P3MEDIUMCVSS 6.5≥ 2.4.0, < 2.4.662025-12-05
CVE-2025-65082 [MEDIUM] CWE-150 CVE-2025-65082: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server th
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs.
This issue affects Apache HTTP Server from 2.4.0 through 2.4.65.
Users are recommended to upgrade to version 2
nvd
CVE-2003-0016P3HIGHCVSS 7.5v2.0.36v2.0.37+6 more2003-02-07
CVE-2003-0016 [HIGH] CVE-2003-0016: Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote a
Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.
nvd
CVE-2013-6438P3MEDIUMCVSS 5.0≥ 2.2.0, < 2.2.27≥ 2.4.1, < 2.4.92014-03-18
CVE-2013-6438 [MEDIUM] CVE-2013-6438: The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before
The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.
nvd
CVE-2019-0220P3MEDIUMCVSS 5.3≥ 2.4.0, ≤ 2.4.382019-06-11
CVE-2019-0220 [MEDIUM] CWE-706 CVE-2019-0220: A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a reques
A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions while other aspects of the servers processing will implicitly collapse them.
nvd
CVE-2009-3095P3MEDIUMCVSS 5.0≥ 2.0.35, < 2.0.64≥ 2.2.0, < 2.2.142009-09-08
CVE-2009-3095 [MEDIUM] CVE-2009-3095: The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access
The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.
nvd
CVE-2009-1891P3HIGHCVSS 7.1≥ 2.0.35, < 2.0.64≥ 2.2.0, < 2.2.122009-07-10
CVE-2009-1891 [HIGH] CWE-400 CVE-2009-1891: The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion ev
The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).
nvd
CVE-2018-1302P3MEDIUMCVSS 5.9≤ 2.4.292018-03-26
CVE-2018-1302 [MEDIUM] CWE-476 CVE-2018-1302: When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4
When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard to trigger in usual configurations, the reporter and the team could not reproduce it outside debug build
nvd
CVE-2004-0885P3HIGHCVSS 7.5v2.0.35v2.0.36+16 more2004-11-03
CVE-2004-0885 [HIGH] CVE-2004-0885: The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in dir
The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.
nvd
CVE-2003-1307P4MEDIUMCVSS 4.3PoCv2.0v2.0.9+17 more2003-12-31
CVE-2003-1307 [MEDIUM] CVE-2003-1307: The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to
The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port. NOTE: the PHP developer has disputed this vulnerability, saying "The op
nvd
CVE-2000-0913P4MEDIUMCVSS 5.0v0.8.11v0.8.14+8 more2000-12-19
CVE-2000-0913 [MEDIUM] CVE-2000-0913: mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a Rewrit
mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.
nvd
CVE-2003-0993P3HIGHCVSS 7.5v1.3v1.3.1+20 more2004-03-29
CVE-2003-0993 [HIGH] CVE-2003-0993: mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly
mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.
nvd
CVE-2013-1896P3MEDIUMCVSS 4.3≥ 2.2.0, < 2.2.25≥ 2.4.1, < 2.4.62013-07-10
CVE-2013-1896 [MEDIUM] CVE-2013-1896: mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled
mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
nvd
CVE-2014-0098P3MEDIUMCVSS 5.0≥ 2.2.0, < 2.2.27≥ 2.4.1, < 2.4.92014-03-18
CVE-2014-0098 [MEDIUM] CVE-2014-0098: The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server b
The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.
nvd
CVE-2018-1283P3MEDIUMCVSS 5.3≥ 2.4.0, ≤ 2.4.292018-03-26
CVE-2018-1283 [MEDIUM] CVE-2018-1283: In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI a
In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a remote user may influence their content by using a "Session" header. This comes from the "HTTP_SESSION" variable name used by mod_session to forward its data to CGIs, since the prefix "HTTP_" is also used by the A
nvd
CVE-2026-43951P3MEDIUMCVSS 6.5≥ 2.4.0, ≤ 2.4.672026-06-08
CVE-2026-43951 [MEDIUM] CWE-125 CVE-2026-43951: Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple re
Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
nvd
CVE-2026-33523P3MEDIUMCVSS 6.5≥ 2.4.0, < 2.4.672026-05-04
CVE-2026-33523 [MEDIUM] CWE-443 CVE-2026-33523: HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compr
HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers.
This issue affects Apache HTTP Server: from through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
nvd
CVE-2010-2068P3MEDIUMCVSS 5.0v2.2.9v2.2.10+7 more2010-06-18
CVE-2010-2068 [MEDIUM] CWE-200 CVE-2010-2068: mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and
mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in certain configurations involving proxy worker pools, does not properly detect timeouts, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunisti
nvd
CVE-2025-54090P3MEDIUMCVSS 6.3v2.4.642025-07-23
CVE-2025-54090 [MEDIUM] CWE-253 CVE-2025-54090: A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true".
A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true".
Users are recommended to upgrade to version 2.4.65, which fixes the issue.
nvd