cbcvebase.

Apache Http Server vulnerabilities

323 known vulnerabilities affecting apache/http_server.

Total CVEs
323
CISA KEV
5
actively exploited
Public exploits
70
Exploited in wild
22
Severity breakdown
CRITICAL38HIGH107MEDIUM165LOW13

Vulnerabilities

Page 6 of 17
CVE-2019-10082P3CRITICALCVSS 9.1≥ 2.4.18, ≤ 2.4.392019-09-26
CVE-2019-10082 [CRITICAL] CWE-416 CVE-2019-10082: In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could b In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during connection shutdown.
nvd
CVE-2013-5704P3MEDIUMCVSS 5.0v2.2.0v2.2.2+32 more2014-04-15
CVE-2013-5704 [MEDIUM] CVE-2013-5704: The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHe The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."
nvd
CVE-2026-24072P3HIGHCVSS 8.8fixed in 2.4.672026-05-04
CVE-2026-24072 [HIGH] CWE-269 CVE-2026-24072: An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .ht An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which fixes this issue.
nvd
CVE-2004-0492P3CRITICALCVSS 10.0v1.3.26v1.3.27+3 more2004-08-06
CVE-2004-0492 [CRITICAL] CVE-2004-0492: Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote at Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.
nvd
CVE-2000-0505P4MEDIUMCVSS 5.0PoCv1.3.6v1.3.9+2 more2000-05-31
CVE-2000-0505 [MEDIUM] CVE-2000-0505: The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory content The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.
nvd
CVE-2025-23048P3CRITICALCVSS 9.1≥ 2.4.35, < 2.4.642025-07-10
CVE-2025-23048 [CRITICAL] CWE-284 CVE-2025-23048: In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control byp In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected when mod_ssl is configured for multiple virtual hosts, with each restricted to a different set of trusted client certificates (for example with a diffe
nvd
CVE-2019-9517P3HIGHCVSS 7.5≥ 2.4.20, < 2.4.402019-08-13
CVE-2019-9517 [HIGH] CWE-400 CVE-2019-9517: Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially lead Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requ
nvd
CVE-2005-2700P3CRITICALCVSS 10.0≥ 2.0.35, < 2.0.552005-09-06
CVE-2005-2700 [CRITICAL] CVE-2005-2700: ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global vi ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
nvd
CVE-2022-36760P3CRITICALCVSS 9.0≥ 2.4.0, < 2.4.552023-01-17
CVE-2022-36760 [CRITICAL] CWE-444 CVE-2022-36760: Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_a Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.54 and prior versions.
nvd
CVE-2019-0215P3HIGHCVSS 7.5v2.4.37v2.4.382019-04-08
CVE-2019-0215 [HIGH] CVE-2019-0215: In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location clien In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a client to bypass configured access control restrictions.
nvd
CVE-1999-0070P4MEDIUMCVSS 5.0PoCfixed in 1.3.01996-04-01
CVE-1999-0070 [MEDIUM] CVE-1999-0070: test-cgi program allows an attacker to list files on the server. test-cgi program allows an attacker to list files on the server.
nvd
CVE-2025-58098P3HIGHCVSS 8.3fixed in 2.4.662025-12-05
CVE-2025-58098 [HIGH] CWE-201 CVE-2025-58098: Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.
nvd
CVE-2004-0488P3HIGHCVSS 7.5≥ 2.0.35, < 2.0.502004-07-07
CVE-2004-0488 [HIGH] CWE-787 CVE-2004-0488: Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ss Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.
nvd
CVE-2010-0010P3MEDIUMCVSS 6.8≤ 1.3.41v0.8.11+44 more2010-02-02
CVE-2010-0010 [MEDIUM] CWE-189 CVE-2010-0010: Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache H Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a large chunk size that triggers a heap-based buffer overflow.
nvd
CVE-2022-28615P3CRITICALCVSS 9.1fixed in 2.4.542022-06-09
CVE-2022-28615 [CRITICAL] CWE-190 CVE-2022-28615: Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua scripts that use ap_strcmp_match() may hypothetically be affected.
nvd
CVE-1999-0926P4CRITICALCVSS 10.0PoCv1.2.51999-09-03
CVE-1999-0926 [CRITICAL] CVE-1999-0926: Apache allows remote attackers to conduct a denial of service via a large number of MIME headers. Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.
nvd
CVE-2001-0766P4CRITICALCVSS 9.8PoCv1.3.142001-10-18
CVE-2001-0766 [CRITICAL] CWE-178 CVE-2001-0766: Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access r Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.
nvd
CVE-2004-0173P4MEDIUMCVSS 5.0PoCv0.8.11v0.8.14+9 more2004-04-15
CVE-2004-0173 [MEDIUM] CVE-2004-0173: Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.
nvd
CVE-2007-6750P3MEDIUMCVSS 5.0≤ 2.2.14v1.0+113 more2011-12-27
CVE-2007-6750 [MEDIUM] CWE-399 CVE-2007-6750: The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outa The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.
nvd
CVE-2020-1927P3MEDIUMCVSS 6.1≥ 2.4.0, ≤ 2.4.412020-04-02
CVE-2020-1927 [MEDIUM] CWE-601 CVE-2020-1927: In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to b In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.
nvd
Apache Http Server vulnerabilities | cvebase