cbcvebase.

Apache Http Server vulnerabilities

323 known vulnerabilities affecting apache/http_server.

Total CVEs
323
CISA KEV
5
actively exploited
Public exploits
70
Exploited in wild
22
Severity breakdown
CRITICAL38HIGH107MEDIUM165LOW13

Vulnerabilities

Page 8 of 17
CVE-2025-53020P3HIGHCVSS 7.5≥ 2.4.17, < 2.4.642025-07-10
CVE-2025-53020 [HIGH] CWE-401 CVE-2025-53020: Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue aff Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.
nvd
CVE-2023-38709P3HIGHCVSS 7.3fixed in 2.4.592024-04-04
CVE-2023-38709 [HIGH] CWE-1284 CVE-2023-38709: Faulty input validation in the core of Apache allows malicious or exploitable backend/content genera Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.
nvd
CVE-2026-34355P3HIGHCVSS 7.5≥ 2.4.0, < 2.4.682026-06-08
CVE-2026-34355 [HIGH] CWE-122 CVE-2026-34355: A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
nvd
CVE-2026-42536P3HIGHCVSS 7.5≥ 2.4.0, < 2.4.682026-06-08
CVE-2026-42536 [HIGH] CWE-122 CVE-2026-42536: Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
nvd
CVE-2013-1862P3MEDIUMCVSS 5.1≥ 2.0.0, < 2.0.65≥ 2.2.0, < 2.2.252013-06-10
CVE-2013-1862 [MEDIUM] CVE-2013-1862: mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.
nvd
CVE-2026-34059P3HIGHCVSS 7.5fixed in 2.4.672026-05-04
CVE-2026-34059 [HIGH] CWE-126 CVE-2026-34059: Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: throug Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
nvd
CVE-2026-44186P3HIGHCVSS 7.3≥ 2.4.0, < 2.4.682026-06-08
CVE-2026-44186 [HIGH] CWE-835 CVE-2026-44186: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue affects undefined: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
nvd
CVE-2017-9789P3HIGHCVSS 7.5v2.4.262017-07-13
CVE-2017-9789 [HIGH] CWE-416 CVE-2017-9789: When under stress, closing many connections, the HTTP/2 handling code in Apache httpd 2.4.26 would s When under stress, closing many connections, the HTTP/2 handling code in Apache httpd 2.4.26 would sometimes access memory after it has been freed, resulting in potentially erratic behaviour.
nvd
CVE-2024-43394P3HIGHCVSS 7.5≥ 2.4.0, < 2.4.642025-07-10
CVE-2024-43394 [HIGH] CWE-918 CVE-2024-43394: Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via mod_rewrite or apache expressions that pass unvalidated request input. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.63. Note: The Apache HTTP Server Project will be setting a higher bar for accepting vu
nvd
CVE-2026-48913P3HIGHCVSS 7.3≥ 2.4.55, < 2.4.682026-06-08
CVE-2026-48913 [HIGH] CWE-416 CVE-2026-48913: Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already ex Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.
nvd
CVE-2024-43204P3HIGHCVSS 7.5≥ 2.4.0, < 2.4.642025-07-10
CVE-2024-43204 [HIGH] CWE-918 CVE-2024-43204: SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker. Requires an unlikely configuration where mod_headers is configured to modify the Content-Type request or response header with a value provided in the HTTP request. Users are recommended to upgrade to version 2.4.64 w
nvd
CVE-2026-34356P3HIGHCVSS 7.5≥ 2.4.0, < 2.4.682026-06-08
CVE-2026-34356 [HIGH] CWE-122 CVE-2026-34356: Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and Pr Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
nvd
CVE-2026-29169P3HIGHCVSS 7.5fixed in 2.4.672026-05-04
CVE-2026-29169 [HIGH] CWE-476 CVE-2026-29169: A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an att A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0. Users are recommended to upgra
nvd
CVE-2026-29168P3HIGHCVSS 7.3≥ 2.4.30, < 2.4.672026-05-05
CVE-2026-29168 [HIGH] CWE-770 CVE-2026-29168: Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md v Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
nvd
CVE-2022-30556P3HIGHCVSS 7.5fixed in 2.4.542022-06-09
CVE-2022-30556 [HIGH] CWE-200 CVE-2022-30556: Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that poi Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.
nvd
CVE-2013-2249P3HIGHCVSS 7.5≥ 2.4.1, ≤ 2.4.42013-07-23
CVE-2013-2249 [HIGH] CVE-2013-2249: mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors.
nvd
CVE-2024-47252P3HIGHCVSS 7.5≥ 2.4.0, < 2.4.642025-07-10
CVE-2024-47252 [HIGH] CWE-150 CVE-2024-47252: Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allo Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where CustomLog is used with "%{varname}x" or "%{varname}c" to log variables provided by mod_ssl such as SSL_TLS_SNI, no escapi
nvd
CVE-2025-55753P3HIGHCVSS 7.5≥ 2.4.30, < 2.4.662025-12-05
CVE-2025-55753 [HIGH] CWE-190 CVE-2025-55753: An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. Users are recommended to u
nvd
CVE-2015-3185P3MEDIUMCVSS 4.3v2.4.0v2.4.1+10 more2015-07-20
CVE-2015-3185 [MEDIUM] CWE-264 CVE-2015-3185: The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the pres
nvd
CVE-2003-0020P4MEDIUMCVSS 5.0PoC≥ 1.3.0, < 1.3.31≥ 2.0.0, < 2.0.492003-03-18
CVE-2003-0020 [MEDIUM] CVE-2003-0020: Apache does not filter terminal escape sequences from its error logs, which could make it easier for Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.
nvd
Apache Http Server vulnerabilities | cvebase