cbcvebase.

Apache Http Server vulnerabilities

323 known vulnerabilities affecting apache/http_server.

Total CVEs
323
CISA KEV
5
actively exploited
Public exploits
70
Exploited in wild
22
Severity breakdown
CRITICAL38HIGH107MEDIUM165LOW13

Vulnerabilities

Page 7 of 17
CVE-2004-0940P4HIGHCVSS 7.8PoC≥ 1.3, ≤ 1.3.322005-02-09
CVE-2004-0940 [HIGH] CWE-131 CVE-2004-0940: Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.
nvd
CVE-2020-1934P3MEDIUMCVSS 5.3≥ 2.4.0, ≤ 2.4.412020-04-01
CVE-2020-1934 [MEDIUM] CWE-908 CVE-2020-1934: In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
nvd
CVE-2002-2272P4HIGHCVSS 7.8PoCv1.3v1.3.0+19 more2002-12-31
CVE-2002-2272 [HIGH] CWE-119 CVE-2002-2272: Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote att Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.
nvd
CVE-2002-0654P4MEDIUMCVSS 5.0PoCv2.0v2.0.28+7 more2002-09-05
CVE-2002-0654 [MEDIUM] CVE-2002-0654: Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked.
nvd
CVE-2018-17199P3HIGHCVSS 7.5≥ 2.4.0, ≤ 2.4.372019-01-30
CVE-2018-17199 [HIGH] CWE-384 CVE-2018-17199: In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time befor In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.
nvd
CVE-2011-3607P4MEDIUMCVSS 4.4PoCv2.0v2.0.9+51 more2011-11-08
CVE-2011-3607 [MEDIUM] CWE-189 CVE-2011-3607: Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, leading to a heap-based buffer ov
nvd
CVE-2026-42535P3CRITICALCVSS 9.1fixed in 2.4.682026-06-08
CVE-2026-42535 [CRITICAL] CWE-668 CVE-2026-42535: A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to d A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
nvd
CVE-2022-37436P3MEDIUMCVSS 5.3fixed in 2.4.552023-01-17
CVE-2022-37436 [MEDIUM] CWE-113 CVE-2022-37436: Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncat Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.
nvd
CVE-2016-2161P3HIGHCVSS 7.5v2.4.0v2.4.1+15 more2017-07-27
CVE-2016-2161 [HIGH] CWE-823 CVE-2016-2161: In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the ser In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for subsequently valid requests.
nvd
CVE-2017-15710P3HIGHCVSS 7.5v2.4.1v2.4.2+17 more2018-03-26
CVE-2017-15710 [HIGH] CWE-787 CVE-2017-15710: In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configur In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user's credentials. If the header value is not present in the charset conversion table, a fallback mechanism is used to truncate
nvd
CVE-2021-30641P3MEDIUMCVSS 5.3≥ 2.4.39, ≤ 2.4.462021-06-10
CVE-2021-30641 [MEDIUM] CVE-2021-30641: Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF' Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'
nvd
CVE-2016-8743P3HIGHCVSS 7.5≥ 2.2.0, ≤ 2.2.31≥ 2.4.1, ≤ 2.4.232017-07-27
CVE-2016-8743 [HIGH] CVE-2016-8743: Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accept Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers, either through mod_proxy or using conventio
nvd
CVE-2019-10081P3HIGHCVSS 7.5≥ 2.4.20, ≤ 2.4.392019-08-15
CVE-2019-10081 [HIGH] CWE-787 CVE-2019-10081: HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", coul HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes. The memory copied is that of the configured push link header values, not data supplied by the client.
nvd
CVE-2001-0042P4MEDIUMCVSS 5.0PoCv1.32001-02-16
CVE-2001-0042 [MEDIUM] CVE-2001-0042: PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (do PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.
nvd
CVE-2025-59775P3HIGHCVSS 7.5≥ 2.4.0, < 2.4.662025-12-05
CVE-2025-59775 [HIGH] CWE-918 CVE-2025-59775: Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server on Windows with AllowEnc Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.66, which fixes the issue.
nvd
CVE-2018-1333P3HIGHCVSS 7.5≥ 2.4.18, ≤ 2.4.30v2.4.332018-06-18
CVE-2018-1333 [HIGH] CWE-400 CVE-2018-1333: By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).
nvd
CVE-2003-0083P4MEDIUMCVSS 5.0PoC≥ 1.3.0, < 1.3.26≥ 2.0.0, < 2.0.462003-04-02
CVE-2003-0083 [MEDIUM] CVE-2003-0083: Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequen Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.
nvd
CVE-2024-38477P3HIGHCVSS 7.5≥ 2.4.0, < 2.4.602024-07-01
CVE-2024-38477 [HIGH] CWE-476 CVE-2024-38477: null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
nvd
CVE-2026-44185P3HIGHCVSS 7.3≥ 2.4.0, < 2.4.682026-06-08
CVE-2026-44185 [HIGH] CWE-126 CVE-2026-44185: Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker contr Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
nvd
CVE-1999-0107P4MEDIUMCVSS 5.0PoCv0.8.11v0.8.14+7 more1997-12-30
CVE-1999-0107 [MEDIUM] CVE-1999-0107: Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service wi Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.
nvd
Apache Http Server vulnerabilities | cvebase