Apache Http Server vulnerabilities
323 known vulnerabilities affecting apache/http_server.
Total CVEs
323
CISA KEV
5
actively exploited
Public exploits
70
Exploited in wild
22
Severity breakdown
CRITICAL38HIGH107MEDIUM165LOW13
Vulnerabilities
Page 13 of 17
CVE-2003-0189P4MEDIUMCVSS 5.0v2.0.40v2.0.41+4 more2003-06-09
CVE-2003-0189 [MEDIUM] CVE-2003-0189: The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads
The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used.
nvd
CVE-2006-5752P4MEDIUMCVSS 4.3≥ 1.3.2, < 1.3.39≥ 2.0.0, < 2.0.61+1 more2007-06-27
CVE-2006-5752 [MEDIUM] CVE-2006-5752: Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Ser
Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type i
nvd
CVE-1999-1199P4CRITICALCVSS 10.0≤ 1.3.11998-08-07
CVE-1999-1199 [CRITICAL] CVE-1999-1199: Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource e
Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the "sioux" vulnerability.
nvd
CVE-2026-34032P4MEDIUMCVSS 5.3fixed in 2.4.672026-05-04
CVE-2026-34032 [MEDIUM] CWE-125 CVE-2026-34032: Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affec
Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
nvd
CVE-2026-33857P4MEDIUMCVSS 5.3fixed in 2.4.672026-05-04
CVE-2026-33857 [MEDIUM] CWE-125 CVE-2026-33857: Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apach
Out-of-bounds Read vulnerability in mod_proxy_ajp of
Apache HTTP Server.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
nvd
CVE-2026-33006P4MEDIUMCVSS 4.8fixed in 2.4.672026-05-04
CVE-2026-33006 [MEDIUM] CWE-208 CVE-2026-33006: A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authe
A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker.
Users are recommended to upgrade to version 2.4.67, which fixes this issue.
nvd
CVE-2003-0987P4HIGHCVSS 7.5≤ 1.3.302004-03-03
CVE-2003-0987 [HIGH] CVE-2003-0987: mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using
mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.
nvd
CVE-2014-3583P4MEDIUMCVSS 5.0v2.4.102014-12-15
CVE-2014-3583 [MEDIUM] CWE-119 CVE-2014-3583: The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Serv
The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long response headers.
nvd
CVE-2022-28330P4MEDIUMCVSS 5.3≤ 2.4.532022-06-09
CVE-2022-28330 [MEDIUM] CWE-125 CVE-2022-28330: Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process r
Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.
nvd
CVE-2024-39884P4MEDIUMCVSS 6.2v2.4.602024-07-04
CVE-2024-39884 [MEDIUM] CWE-668 CVE-2024-39884: A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type ba
A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted.
Users
nvd
CVE-2026-29170P4MEDIUMCVSS 6.1fixed in 2.4.682026-06-08
CVE-2026-29170 [MEDIUM] CWE-79 CVE-2026-29170: A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apa
A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
nvd
CVE-2002-1156P4MEDIUMCVSS 5.0v2.0.422002-10-11
CVE-2002-1156 [MEDIUM] CVE-2002-1156: Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to
Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled.
nvd
CVE-2001-0730P4MEDIUMCVSS 5.0v1.3.202001-10-30
CVE-2001-0730 [MEDIUM] CVE-2001-0730: split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the
split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header.
nvd
CVE-2004-0748P4MEDIUMCVSS 5.0≥ 2.0.35, < 2.0.512004-10-20
CVE-2004-0748 [MEDIUM] CWE-835 CVE-2004-0748: mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consu
mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop.
nvd
CVE-2024-36387P4MEDIUMCVSS 5.4≥ 2.4.55, ≤ 2.4.592024-07-01
CVE-2024-36387 [MEDIUM] CWE-476 CVE-2024-36387: Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer derefere
Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.
nvd
CVE-2005-3357P4MEDIUMCVSS 5.4v2.0v2.0.9+23 more2005-12-31
CVE-2005-3357 [MEDIUM] CWE-399 CVE-2005-3357: mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a cust
mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference.
nvd
CVE-2005-2088P4MEDIUMCVSS 4.3≥ 2.0.35, < 2.0.552005-07-05
CVE-2005-2088 [MEDIUM] CWE-444 CVE-2005-2088: The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows
The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and f
nvd
CVE-2013-4352P4MEDIUMCVSS 4.3v2.4.62014-07-20
CVE-2013-4352 [MEDIUM] CVE-2013-4352: The cache_invalidate function in modules/cache/cache_storage.c in the mod_cache module in the Apache
The cache_invalidate function in modules/cache/cache_storage.c in the mod_cache module in the Apache HTTP Server 2.4.6, when a caching forward proxy is enabled, allows remote HTTP servers to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger a missing hostname value.
nvd
CVE-2004-0786P4MEDIUMCVSS 5.0≥ 2.0.35, < 2.0.512004-10-20
CVE-2004-0786 [MEDIUM] CVE-2004-0786: The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote att
The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool.
nvd
CVE-2004-0747P4HIGHCVSS 7.8≥ 2.0.35, < 2.0.512004-10-20
CVE-2004-0747 [HIGH] CWE-131 CVE-2004-0747: Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .hta
Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.
nvd