cbcvebase.

Apache Software Foundation Apache Http Server vulnerabilities

115 known vulnerabilities affecting apache_software_foundation/apache_http_server.

Total CVEs
115
CISA KEV
3
actively exploited
Public exploits
14
Exploited in wild
14
Severity breakdown
CRITICAL25HIGH61MEDIUM29

Vulnerabilities

Page 5 of 6
CVE-2026-29168P3HIGHCVSS 7.3≥ 2.4.30, ≤ 2.4.662026-05-05
CVE-2026-29168 [HIGH] CWE-770 CVE-2026-29168: Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md v Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
nvd
CVE-2022-30556P3HIGHCVSS 7.5≥ unspecified, ≤ 2.4.532022-06-09
CVE-2022-30556 [HIGH] CWE-200 CVE-2022-30556: Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that poi Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.
nvd
CVE-2024-47252P3HIGHCVSS 7.5≥ 2.4, ≤ 2.4.632025-07-10
CVE-2024-47252 [HIGH] CWE-150 CVE-2024-47252: Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allo Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where CustomLog is used with "%{varname}x" or "%{varname}c" to log variables provided by mod_ssl such as SSL_TLS_SNI, no escapi
nvd
CVE-2025-55753P3HIGHCVSS 7.5≥ 2.4.30, < 2.4.662025-12-05
CVE-2025-55753 [HIGH] CWE-190 CVE-2025-55753: An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. Users are recommended to u
nvd
CVE-2024-40898P3HIGHCVSS 7.5≥ 2.4.0, ≤ 2.4.612024-07-18
CVE-2024-40898 [HIGH] CWE-918 CVE-2024-40898: SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentiall SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue.
nvd
CVE-2025-49812P3HIGHCVSS 7.4≤ 2.4.632025-07-10
CVE-2025-49812 [HIGH] CWE-287 CVE-2025-49812: In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchroni In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upgrades are affected. Users are recommended to upgrade to version 2.4.64, which removes support
nvd
CVE-2023-31122P3HIGHCVSS 7.5≤ 2.4.572023-10-23
CVE-2023-31122 [HIGH] CWE-125 CVE-2023-31122: Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP S Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.
nvd
CVE-2019-0196P3MEDIUMCVSS 5.3v2.4.17 to 2.4.382019-06-11
CVE-2019-0196 [MEDIUM] CWE-416 CVE-2019-0196: A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the ht A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access freed memory in string comparison when determining the method of a request and thus process the request incorrectly.
nvd
CVE-2025-49630P3HIGHCVSS 7.5≥ 2.4.26, ≤ 2.4.632025-07-10
CVE-2025-49630 [HIGH] CWE-617 CVE-2025-49630: In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4. In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".
nvd
CVE-2022-29404P3HIGHCVSS 7.5≥ unspecified, ≤ 2.4.532022-06-09
CVE-2022-29404 [HIGH] CWE-770 CVE-2022-29404: In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size.
nvd
CVE-2018-1301P3MEDIUMCVSS 5.9v2.2.0 to 2.4.292018-03-26
CVE-2018-1301 [MEDIUM] CWE-119 CVE-2018-1301: A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due t A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very hard if not impossible to trigger in non-debug mode (both log and build level), so it is classified as low risk for common server us
nvd
CVE-2023-27522P3HIGHCVSS 7.5≥ 2.4.30, ≤ 2.4.552023-03-07
CVE-2023-27522 [HIGH] CWE-444 CVE-2023-27522: HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.
nvd
CVE-2018-17189P3MEDIUMCVSS 5.3v2.4.17 to 2.4.372019-01-30
CVE-2018-17189 [MEDIUM] CWE-400 CVE-2018-17189: In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to pl In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connections.
nvd
CVE-2006-20001P3HIGHCVSS 7.5≥ 2.4, ≤ 2.4.542023-01-17
CVE-2006-20001 [HIGH] CWE-787 CVE-2006-20001: A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash. This issue affects Apache HTTP Server 2.4.54 and earlier.
nvd
CVE-2025-65082P3MEDIUMCVSS 6.5≥ 2.4.0, ≤ 2.4.652025-12-05
CVE-2025-65082 [MEDIUM] CWE-150 CVE-2025-65082: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server th Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2
nvd
CVE-2019-0220P3MEDIUMCVSS 5.3v2.4.0 to 2.4.382019-06-11
CVE-2019-0220 [MEDIUM] CWE-706 CVE-2019-0220: A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a reques A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions while other aspects of the servers processing will implicitly collapse them.
nvd
CVE-2018-1302P3MEDIUMCVSS 5.9v2.4.17 to 2.4.292018-03-26
CVE-2018-1302 [MEDIUM] CWE-476 CVE-2018-1302: When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4 When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard to trigger in usual configurations, the reporter and the team could not reproduce it outside debug build
nvd
CVE-2018-1283P3MEDIUMCVSS 5.3v2.4.0 to 2.4.292018-03-26
CVE-2018-1283 [MEDIUM] CVE-2018-1283: In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI a In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a remote user may influence their content by using a "Session" header. This comes from the "HTTP_SESSION" variable name used by mod_session to forward its data to CGIs, since the prefix "HTTP_" is also used by the A
nvd
CVE-2026-43951P3MEDIUMCVSS 6.5≥ 2.4.0, ≤ 2.4.672026-06-08
CVE-2026-43951 [MEDIUM] CWE-125 CVE-2026-43951: Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple re Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
nvd
CVE-2026-33523P3MEDIUMCVSS 6.5≥ 2.4.0, ≤ 2.4.662026-05-04
CVE-2026-33523 [MEDIUM] CWE-443 CVE-2026-33523: HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compr HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP Server: from through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
nvd
Apache Software Foundation Apache Http Server vulnerabilities | cvebase