Apache Software Foundation Apache Http Server vulnerabilities
115 known vulnerabilities affecting apache_software_foundation/apache_http_server.
Total CVEs
115
CISA KEV
3
actively exploited
Public exploits
14
Exploited in wild
14
Severity breakdown
CRITICAL25HIGH61MEDIUM29
Vulnerabilities
Page 6 of 6
CVE-2025-54090P3MEDIUMCVSS 6.3v2.4.642025-07-23
CVE-2025-54090 [MEDIUM] CWE-253 CVE-2025-54090: A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true".
A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true".
Users are recommended to upgrade to version 2.4.65, which fixes the issue.
nvd
CVE-2024-24795P3MEDIUMCVSS 6.3≥ 2.4.0, ≤ 2.4.582024-04-04
CVE-2024-24795 [MEDIUM] CWE-113 CVE-2024-24795: HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject
HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack.
Users are recommended to upgrade to version 2.4.59, which fixes this issue.
nvd
CVE-2025-66200P4MEDIUMCVSS 5.4≥ 2.4.7, ≤ 2.4.652025-12-05
CVE-2025-66200 [MEDIUM] CWE-288 CVE-2025-66200: mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with
mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid.
This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65.
Users are recommended to upgrade to version 2.4.66, which fixes th
nvd
CVE-2026-33007P4MEDIUMCVSS 5.3≥ 2.4.0, ≤ 2.4.662026-05-04
CVE-2026-33007 [MEDIUM] CWE-476 CVE-2026-33007: A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows
A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration.
Users are recommended to upgrade to version 2.4.67, which fixes this issue.
nvd
CVE-2020-13938P4MEDIUMCVSS 5.5v2.4.46v2.4.43+27 more2021-06-10
CVE-2020-13938 [MEDIUM] CWE-862 CVE-2020-13938: Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows
Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows
nvd
CVE-2022-28614P4MEDIUMCVSS 5.3≥ unspecified, ≤ 2.4.532022-06-09
CVE-2022-28614 [MEDIUM] CWE-190 CVE-2022-28614: The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an a
The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts() function. Modules compiled and distributed separately from Apache HTTP Server that use the 'ap_rputs' function and may pass it a v
nvd
CVE-2026-34032P4MEDIUMCVSS 5.3≤ 2.4.662026-05-04
CVE-2026-34032 [MEDIUM] CWE-125 CVE-2026-34032: Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affec
Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
nvd
CVE-2026-33857P4MEDIUMCVSS 5.3≤ 2.4.662026-05-04
CVE-2026-33857 [MEDIUM] CWE-125 CVE-2026-33857: Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apach
Out-of-bounds Read vulnerability in mod_proxy_ajp of
Apache HTTP Server.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
nvd
CVE-2026-33006P4MEDIUMCVSS 4.8≤ 2.4.662026-05-04
CVE-2026-33006 [MEDIUM] CWE-208 CVE-2026-33006: A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authe
A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker.
Users are recommended to upgrade to version 2.4.67, which fixes this issue.
nvd
CVE-2022-28330P4MEDIUMCVSS 5.3≥ Apache HTTP Server, ≤ 2.4.532022-06-09
CVE-2022-28330 [MEDIUM] CWE-125 CVE-2022-28330: Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process r
Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.
nvd
CVE-2024-39884P4MEDIUMCVSS 6.2≥ 2.4.60, ≤ 2.4.612024-07-04
CVE-2024-39884 [MEDIUM] CWE-668 CVE-2024-39884: A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type ba
A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted.
Users
nvd
CVE-2026-29170P4MEDIUMCVSS 6.1≤ 2.4.672026-06-08
CVE-2026-29170 [MEDIUM] CWE-79 CVE-2026-29170: A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apa
A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
nvd
CVE-2024-36387P4MEDIUMCVSS 5.4≥ 2.4.55, ≤ 2.4.592024-07-01
CVE-2024-36387 [MEDIUM] CWE-476 CVE-2024-36387: Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer derefere
Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.
nvd
CVE-2019-0197P4MEDIUMCVSS 4.2v2.4.34 to 2.4.382019-06-11
CVE-2019-0197 [MEDIUM] CWE-444 CVE-2019-0197: A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http
A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection could lead to a misconfiguration and crash. Server that never enabled the h2 protocol or that only enabled
nvd
CVE-2026-44119P4MEDIUMCVSS 5.5≥ 2.4.0, ≤ 2.4.672026-06-08
CVE-2026-44119 [MEDIUM] CWE-269 CVE-2026-44119: Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .h
Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.
This issue affects Apache HTTP Server: from through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
nvd
← Previous6 / 6