cbcvebase.

Apache Http Server vulnerabilities

323 known vulnerabilities affecting apache/http_server.

Total CVEs
323
CISA KEV
5
actively exploited
Public exploits
70
Exploited in wild
22
Severity breakdown
CRITICAL38HIGH107MEDIUM165LOW13

Vulnerabilities

Page 9 of 17
CVE-2009-2699P3HIGHCVSS 7.5≥ 2.2.0, < 2.2.142009-10-13
CVE-2009-2699 [HIGH] CWE-667 CVE-2009-2699: The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Run The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the Apache HTTP Server before 2.2.14 and other products, does not properly handle errors, which allows remote attackers to cause a denial of service (daemon hang) via unspecified HTTP requests, related to the pr
nvd
CVE-2007-6388P4MEDIUMCVSS 4.3≥ 1.3.2, ≤ 1.3.39≥ 2.0.35, ≤ 2.0.61+1 more2008-01-08
CVE-2007-6388 [MEDIUM] CWE-79 CVE-2007-6388: Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6 Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2024-40898P3HIGHCVSS 7.5fixed in 2.4.622024-07-18
CVE-2024-40898 [HIGH] CWE-918 CVE-2024-40898: SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentiall SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue.
nvd
CVE-2024-42516P3HIGHCVSS 7.5≥ 2.4.0, < 2.4.642025-07-10
CVE-2024-42516 [HIGH] CVE-2024-42516: HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 but the patch included in Apache HTTP Server 2.4.59 did not address the issue. Users are recommended t
nvd
CVE-2025-49812P3HIGHCVSS 7.4fixed in 2.4.642025-07-10
CVE-2025-49812 [HIGH] CWE-287 CVE-2025-49812: In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchroni In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upgrades are affected. Users are recommended to upgrade to version 2.4.64, which removes support
nvd
CVE-2005-3352P4MEDIUMCVSS 4.3fixed in 1.3.35≥ 2.0, < 2.0.56+1 more2005-12-13
CVE-2005-3352 [MEDIUM] CWE-79 CVE-2005-3352: Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev an Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
nvd
CVE-2023-31122P3HIGHCVSS 7.5fixed in 2.4.582023-10-23
CVE-2023-31122 [HIGH] CWE-125 CVE-2023-31122: Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP S Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.
nvd
CVE-2019-0196P3MEDIUMCVSS 5.3≥ 2.4.17, ≤ 2.4.382019-06-11
CVE-2019-0196 [MEDIUM] CWE-416 CVE-2019-0196: A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the ht A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access freed memory in string comparison when determining the method of a request and thus process the request incorrectly.
nvd
CVE-2014-0231P3MEDIUMCVSS 5.0≥ 2.2.0, < 2.2.29≥ 2.4.0, < 2.4.102014-07-20
CVE-2014-0231 [MEDIUM] CWE-399 CVE-2014-0231: The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor.
nvd
CVE-2025-49630P3HIGHCVSS 7.5≥ 2.4.26, < 2.4.642025-07-10
CVE-2025-49630 [HIGH] CWE-617 CVE-2025-49630: In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4. In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".
nvd
CVE-2012-0031P4MEDIUMCVSS 4.6PoC≥ 2.0.0, < 2.0.65≥ 2.2.0, < 2.2.222012-01-18
CVE-2012-0031 [MEDIUM] CVE-2012-0031: scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function.
nvd
CVE-2022-29404P3HIGHCVSS 7.5≤ 2.4.532022-06-09
CVE-2022-29404 [HIGH] CWE-770 CVE-2022-29404: In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size.
nvd
CVE-2018-1301P3MEDIUMCVSS 5.9≤ 2.4.292018-03-26
CVE-2018-1301 [MEDIUM] CWE-119 CVE-2018-1301: A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due t A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very hard if not impossible to trigger in non-debug mode (both log and build level), so it is classified as low risk for common server us
nvd
CVE-2002-0843P3HIGHCVSS 7.5v1.3v1.3.1+16 more2002-10-11
CVE-2002-0843 [HIGH] CVE-2002-0843: Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Ap Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response.
nvd
CVE-2006-4154P3MEDIUMCVSS 6.8v2.0v2.0.9+38 more2006-10-16
CVE-2006-4154 [MEDIUM] CVE-2006-4154: Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attack Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a set_var function call in (1) tcl_cmds.c and (2) tcl_core.c.
nvd
CVE-2023-27522P3HIGHCVSS 7.5≥ 2.4.30, < 2.4.562023-03-07
CVE-2023-27522 [HIGH] CWE-444 CVE-2023-27522: HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.
nvd
CVE-2014-8109P3MEDIUMCVSS 4.3v2.4.1v2.4.2+6 more2014-12-29
CVE-2014-8109 [MEDIUM] CWE-863 CVE-2014-8109: mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not su mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging multi
nvd
CVE-2018-17189P3MEDIUMCVSS 5.3v2.4.17v2.4.18+12 more2019-01-30
CVE-2018-17189 [MEDIUM] CWE-400 CVE-2018-17189: In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to pl In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connections.
nvd
CVE-2014-0118P3MEDIUMCVSS 4.3≥ 2.2.0, < 2.2.29≥ 2.4.1, < 2.4.102014-07-20
CVE-2014-0118 [MEDIUM] CWE-400 CVE-2014-0118: The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses to a much larger size.
nvd
CVE-2006-20001P3HIGHCVSS 7.5fixed in 2.4.552023-01-17
CVE-2006-20001 [HIGH] CWE-787 CVE-2006-20001: A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash. This issue affects Apache HTTP Server 2.4.54 and earlier.
nvd
Apache Http Server vulnerabilities | cvebase