cbcvebase.

Apache Software Foundation Apache Http Server vulnerabilities

115 known vulnerabilities affecting apache_software_foundation/apache_http_server.

Total CVEs
115
CISA KEV
3
actively exploited
Public exploits
14
Exploited in wild
14
Severity breakdown
CRITICAL25HIGH61MEDIUM29

Vulnerabilities

Page 4 of 6
CVE-2016-2161P3HIGHCVSS 7.5v2.4.0 to 2.4.232017-07-27
CVE-2016-2161 [HIGH] CWE-823 CVE-2016-2161: In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the ser In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for subsequently valid requests.
nvd
CVE-2017-15710P3HIGHCVSS 7.5v2.0.23 to 2.0.65v2.2.0 to 2.2.34+1 more2018-03-26
CVE-2017-15710 [HIGH] CWE-787 CVE-2017-15710: In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configur In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user's credentials. If the header value is not present in the charset conversion table, a fallback mechanism is used to truncate
nvd
CVE-2021-30641P3MEDIUMCVSS 5.3v2.4.46v2.4.43+2 more2021-06-10
CVE-2021-30641 [MEDIUM] CVE-2021-30641: Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF' Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'
nvd
CVE-2016-8743P3HIGHCVSS 7.5v2.2.0 to 2.2.31, 2.4.1 to 2.4.232017-07-27
CVE-2016-8743 [HIGH] CVE-2016-8743: Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accept Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers, either through mod_proxy or using conventio
nvd
CVE-2025-59775P3HIGHCVSS 7.5≥ 2.4.0, ≤ 2.4.652025-12-05
CVE-2025-59775 [HIGH] CWE-918 CVE-2025-59775: Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server on Windows with AllowEnc Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.66, which fixes the issue.
nvd
CVE-2018-1333P3HIGHCVSS 7.5vFixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33)2018-06-18
CVE-2018-1333 [HIGH] CWE-400 CVE-2018-1333: By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).
nvd
CVE-2024-38477P3HIGHCVSS 7.5≥ 2.4.0, ≤ 2.4.592024-07-01
CVE-2024-38477 [HIGH] CWE-476 CVE-2024-38477: null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
nvd
CVE-2026-44185P3HIGHCVSS 7.3≥ 2.4.0, ≤ 2.4.672026-06-08
CVE-2026-44185 [HIGH] CWE-126 CVE-2026-44185: Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker contr Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
nvd
CVE-2025-53020P3HIGHCVSS 7.5≥ 2.4.17, ≤ 2.4.632025-07-10
CVE-2025-53020 [HIGH] CWE-401 CVE-2025-53020: Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue aff Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.
nvd
CVE-2023-38709P3HIGHCVSS 7.3≥ 2.4.0, ≤ 2.4.632024-04-04
CVE-2023-38709 [HIGH] CWE-1284 CVE-2023-38709: Faulty input validation in the core of Apache allows malicious or exploitable backend/content genera Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.
nvd
CVE-2026-34355P3HIGHCVSS 7.5≥ 2.4.0, ≤ 2.4.672026-06-08
CVE-2026-34355 [HIGH] CWE-122 CVE-2026-34355: A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
nvd
CVE-2026-42536P3HIGHCVSS 7.5≥ 2.4.0, ≤ 2.4.672026-06-08
CVE-2026-42536 [HIGH] CWE-122 CVE-2026-42536: Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
nvd
CVE-2026-34059P3HIGHCVSS 7.5≤ 2.4.662026-05-04
CVE-2026-34059 [HIGH] CWE-126 CVE-2026-34059: Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: throug Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
nvd
CVE-2026-44186P3HIGHCVSS 7.3≥ 2.4.0, ≤ 2.4.672026-06-08
CVE-2026-44186 [HIGH] CWE-835 CVE-2026-44186: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue affects undefined: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
nvd
CVE-2017-9789P3HIGHCVSS 7.5v2.4.262017-07-13
CVE-2017-9789 [HIGH] CWE-416 CVE-2017-9789: When under stress, closing many connections, the HTTP/2 handling code in Apache httpd 2.4.26 would s When under stress, closing many connections, the HTTP/2 handling code in Apache httpd 2.4.26 would sometimes access memory after it has been freed, resulting in potentially erratic behaviour.
nvd
CVE-2024-43394P3HIGHCVSS 7.5≥ 2.4.0, ≤ 2.4.632025-07-10
CVE-2024-43394 [HIGH] CWE-918 CVE-2024-43394: Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via mod_rewrite or apache expressions that pass unvalidated request input. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.63. Note: The Apache HTTP Server Project will be setting a higher bar for accepting vu
nvd
CVE-2026-48913P3HIGHCVSS 7.3≥ 2.4.55, ≤ 2.4.672026-06-08
CVE-2026-48913 [HIGH] CWE-416 CVE-2026-48913: Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already ex Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.
nvd
CVE-2024-43204P3HIGHCVSS 7.5≥ 2.4.0, ≤ 2.4.632025-07-10
CVE-2024-43204 [HIGH] CWE-918 CVE-2024-43204: SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker. Requires an unlikely configuration where mod_headers is configured to modify the Content-Type request or response header with a value provided in the HTTP request. Users are recommended to upgrade to version 2.4.64 w
nvd
CVE-2026-34356P3HIGHCVSS 7.5≥ 2.4.0, ≤ 2.4.672026-06-08
CVE-2026-34356 [HIGH] CWE-122 CVE-2026-34356: Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and Pr Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
nvd
CVE-2026-29169P3HIGHCVSS 7.5≤ 2.4.662026-05-04
CVE-2026-29169 [HIGH] CWE-476 CVE-2026-29169: A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an att A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0. Users are recommended to upgra
nvd