cbcvebase.

Apache Http Server vulnerabilities

323 known vulnerabilities affecting apache/http_server.

Total CVEs
323
CISA KEV
5
actively exploited
Public exploits
70
Exploited in wild
22
Severity breakdown
CRITICAL38HIGH107MEDIUM165LOW13

Vulnerabilities

Page 5 of 17
CVE-2006-4110P3MEDIUMCVSS 4.3PoCv2.0.58v2.2.2+1 more2006-08-14
CVE-2006-4110 [MEDIUM] CVE-2006-4110: Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs v Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file on case-insensitive file systems.
nvd
CVE-2022-31813P3CRITICALCVSS 9.8fixed in 2.4.542022-06-09
CVE-2022-31813 [CRITICAL] CWE-348 CVE-2022-31813: Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server ba Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.
nvd
CVE-2024-38474P3CRITICALCVSS 9.8≥ 2.4.0, < 2.4.602024-07-01
CVE-2024-38474 [CRITICAL] CWE-116 CVE-2024-38474: Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
nvd
CVE-2017-3169P3CRITICALCVSS 9.8v2.2.0v2.2.2+32 more2017-06-20
CVE-2017-3169 [CRITICAL] CWE-476 CVE-2017-3169: In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_connection() during an HTTP request to an HTTPS port.
nvd
CVE-2019-17567P3MEDIUMCVSS 5.3≥ 2.4.6, ≤ 2.4.462021-06-10
CVE-2019-17567 [MEDIUM] CWE-444 CVE-2019-17567: Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not nece Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.
nvd
CVE-2026-29167P2CRITICALCVSS 9.8≥ 2.4.0, < 2.4.682026-06-08
CVE-2026-29167 [CRITICAL] CWE-416 CVE-2026-29167: Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration Thi Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
nvd
CVE-2026-44631P2CRITICALCVSS 9.8≥ 2.4.0, < 2.4.682026-06-08
CVE-2026-44631 [CRITICAL] CWE-124 CVE-2026-44631: Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configur Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
nvd
CVE-2001-0925P4MEDIUMCVSS 5.0PoCv1.3.11v1.3.12+2 more2001-03-12
CVE-2001-0925 [MEDIUM] CWE-22 CVE-2001-0925: The default installation of Apache before 1.3.19 allows remote attackers to list directories instead The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex.
nvd
CVE-2008-2168P4MEDIUMCVSS 4.3PoCv2.0v2.0.9+44 more2008-05-13
CVE-2008-2168 [MEDIUM] CWE-79 CVE-2008-2168: Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inje Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.
nvd
CVE-2000-0869P4MEDIUMCVSS 5.0PoCv1.3.122000-11-14
CVE-2000-0869 [MEDIUM] CVE-2000-0869: The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote att The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method.
nvd
CVE-2021-41524P3HIGHCVSS 7.5v2.4.492021-10-05
CVE-2021-41524 [HIGH] CWE-476 CVE-2021-41524: While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request pr While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.
nvd
CVE-2019-0217P3HIGHCVSS 7.5≥ 2.4.0, ≤ 2.4.382019-04-08
CVE-2019-0217 [HIGH] CWE-362 CVE-2019-0217: In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.
nvd
CVE-2007-6514P4MEDIUMCVSS 4.3PoCv2.2.62007-12-21
CVE-2007-6514 [MEDIUM] CWE-200 CVE-2007-6514: Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbf Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (backslash), which is not handled by the intended AddType directive.
nvd
CVE-2002-1850P3HIGHCVSS 7.5PoCv2.0.39v2.0.402002-12-31
CVE-2002-1850 [HIGH] CWE-667 CVE-2002-1850: mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a deni mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script.
nvd
CVE-1999-0045P4HIGHCVSS 7.5PoCv0.8.11v0.8.14+5 more1996-12-10
CVE-1999-0045 [HIGH] CVE-1999-0045: List of arbitrary files on Web host via nph-test-cgi script. List of arbitrary files on Web host via nph-test-cgi script.
nvd
CVE-2015-3183P3MEDIUMCVSS 5.0≥ 2.2.0, < 2.2.31≥ 2.4.0, < 2.4.162015-07-20
CVE-2015-3183 [MEDIUM] CWE-17 CVE-2015-3183: The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.
nvd
CVE-2022-26377P3HIGHCVSS 7.5≥ 2.4.0, < 2.4.542022-06-09
CVE-2022-26377 [HIGH] CWE-444 CVE-2022-26377: Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_a Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.
nvd
CVE-1999-0236P4HIGHCVSS 7.5PoCfixed in 1.01997-01-01
CVE-1999-0236 [HIGH] CVE-1999-0236: ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs. ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.
nvd
CVE-2004-0942P4MEDIUMCVSS 5.0PoC≤ 2.0.522005-02-09
CVE-2004-0942 [MEDIUM] CVE-2004-0942: Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consum Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.
nvd
CVE-2011-0419P3MEDIUMCVSS 4.3PoC≥ 2.0.0, ≤ 2.0.65≥ 2.2.0, ≤ 2.2.182011-05-16
CVE-2011-0419 [MEDIUM] CWE-770 CVE-2011-0419: Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portabl Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of ser
nvd
Apache Http Server vulnerabilities | cvebase