Apache HTTP Server
Apache Software Foundation- Product type
- Other
- Catalog vulnerabilities
- 119
en
Severity across 109 analyzed records
Verify to analyze this security profile
As of 09/13/2026, within CyStack's analyzed data, Apache HTTP Server has 0 security vulnerabilities published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Apache HTTP Server and determine which vulnerabilities affect that version.
| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-49975Apache HTTP Server: mod_http2 denial of service | Exploitation statusPublic exploit | FixYes | Published06/08/2026 | SeverityHigh |
CVE-2026-48913Apache HTTP Server: mod_http2 memory corruption when file handles exhausted | Exploitation statusNot known exploited | FixYes | Published06/08/2026 | SeverityHigh |
CVE-2026-42536Apache HTTP Server: mod_xml2enc heap overflow | Exploitation statusNot known exploited | FixYes | Published06/08/2026 | SeverityHigh |
CVE-2026-44185Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request` | Exploitation statusNot known exploited | FixYes | Published06/08/2026 | SeverityHigh |
CVE-2026-34355Apache HTTP Server: mod_proxy_html buffer overflow | Exploitation statusNot known exploited | FixYes | Published06/08/2026 | SeverityHigh |
CVE-2026-44631Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow | Exploitation statusNot known exploited | FixYes | Published06/08/2026 | SeverityCritical |
CVE-2026-44119Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules | Exploitation statusNot known exploited | FixYes | Published06/08/2026 | SeverityMedium |
CVE-2026-43951Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash | Exploitation statusNot known exploited | FixYes | Published06/08/2026 | SeverityMedium |
CVE-2026-42535Apache HTTP Server: mod_dav_fs protected directory access | Exploitation statusNot known exploited | FixYes | Published06/08/2026 | SeverityCritical |
CVE-2026-34356Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow | Exploitation statusNot known exploited | FixYes | Published06/08/2026 | SeverityHigh |
CVE-2026-44186Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp | Exploitation statusNot known exploited | FixYes | Published06/08/2026 | SeverityHigh |
CVE-2026-29170Apache HTTP Server: mod_proxy_ftp XSS | Exploitation statusNot known exploited | FixYes | Published06/08/2026 | SeverityMedium |
CVE-2026-29167Apache HTTP Server: mod_ldap per-dir use-after-free | Exploitation statusNot known exploited | FixYes | Published06/08/2026 | SeverityCritical |
CVE-2026-28780Apache HTTP Server: buffer overflow in mod_proxy_ajp via ajp_msg_check_header() | Exploitation statusNot known exploited | FixYes | Published05/05/2026 | SeverityCritical |
CVE-2026-29168Apache HTTP Server: mod_md unrestricted OCSP response | Exploitation statusNot known exploited | FixYes | Published05/05/2026 | SeverityHigh |
CVE-2026-29169Apache HTTP Server: mod_dav_lock indirect lock crash | Exploitation statusNot known exploited | FixYes | Published05/04/2026 | SeverityHigh |
CVE-2026-23918Apache HTTP Server: http2: double free and possible RCE on early reset | Exploitation statusNot known exploited | FixYes | Published05/04/2026 | SeverityHigh |
CVE-2026-33006Apache HTTP Server: mod_auth_digest timing attack | Exploitation statusNot known exploited | FixYes | Published05/04/2026 | SeverityMedium |
CVE-2026-33007Apache HTTP Server: mod_authn_socache crash | Exploitation statusNot known exploited | FixYes | Published05/04/2026 | SeverityMedium |
CVE-2026-33523Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line | Exploitation statusNot known exploited | FixYes | Published05/04/2026 | SeverityMedium |
CVE-2026-33857Apache HTTP Server: Off-by-one OOB reads in AJP getter functions | Exploitation statusNot known exploited | FixYes | Published05/04/2026 | SeverityMedium |
CVE-2026-34032Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string) | Exploitation statusNot known exploited | FixYes | Published05/04/2026 | SeverityMedium |
CVE-2026-34059Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data() | Exploitation statusNot known exploited | FixYes | Published05/04/2026 | SeverityHigh |
CVE-2026-24072Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr | Exploitation statusNot known exploited | FixYes | Published05/04/2026 | SeverityHigh |
CVE-2025-58098Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... | Exploitation statusNot known exploited | FixYes | Published12/05/2025 | SeverityHigh |
CVE-2025-66200Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo | Exploitation statusNot known exploited | FixYes | Published12/05/2025 | SeverityMedium |
CVE-2025-65082Apache HTTP Server: CGI environment variable override | Exploitation statusNot known exploited | FixYes | Published12/05/2025 | SeverityMedium |
CVE-2025-59775Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF | Exploitation statusNot known exploited | FixYes | Published12/05/2025 | SeverityHigh |
CVE-2025-55753Apache HTTP Server: mod_md (ACME), unintended retry intervals | Exploitation statusNot known exploited | FixYes | Published12/05/2025 | SeverityHigh |
CVE-2025-54090Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64 | Exploitation statusNot known exploited | FixYes | Published07/23/2025 | SeverityMedium |
CVE-2025-53020Apache HTTP Server: HTTP/2 DoS by Memory Increase | Exploitation statusNot known exploited | FixYes | Published07/10/2025 | SeverityHigh |
CVE-2025-49812Apache HTTP Server: mod_ssl TLS upgrade attack | Exploitation statusNot known exploited | FixYes | Published07/10/2025 | SeverityHigh |
CVE-2025-49630Apache HTTP Server: mod_proxy_http2 denial of service | Exploitation statusNot known exploited | FixYes | Published07/10/2025 | SeverityHigh |
CVE-2025-23048Apache HTTP Server: mod_ssl access control bypass with session resumption | Exploitation statusPublic exploit | FixYes | Published07/10/2025 | SeverityCritical |
CVE-2024-43394Apache HTTP Server: SSRF on Windows due to UNC paths | Exploitation statusNot known exploited | FixYes | Published07/10/2025 | SeverityHigh |
CVE-2024-47252Apache HTTP Server: mod_ssl error log variable escaping | Exploitation statusNot known exploited | FixYes | Published07/10/2025 | SeverityHigh |
CVE-2024-43204Apache HTTP Server: SSRF with mod_headers setting Content-Type header | Exploitation statusNot known exploited | FixYes | Published07/10/2025 | SeverityHigh |
CVE-2024-42516Apache HTTP Server: HTTP response splitting | Exploitation statusNot known exploited | FixYes | Published07/10/2025 | SeverityHigh |
CVE-2024-40725Apache HTTP Server: source code disclosure with handlers configured via AddType | Exploitation statusNot known exploited | FixYes | Published07/18/2024 | SeverityMedium |
CVE-2024-40898Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows | Exploitation statusNot known exploited | FixYes | Published07/18/2024 | SeverityCritical |
CVE-2024-39884Apache HTTP Server: source code disclosure with handlers configured via AddType | Exploitation statusNot known exploited | FixNot confirmed | Published07/04/2024 | SeverityMedium |
CVE-2024-39573Apache HTTP Server: mod_rewrite proxy handler substitution | Exploitation statusNot known exploited | FixYes | Published07/01/2024 | SeverityHigh |
CVE-2024-38477Apache HTTP Server: Crash resulting in Denial of Service in mod_proxy via a malicious request | Exploitation statusNot known exploited | FixYes | Published07/01/2024 | SeverityHigh |
CVE-2024-38476Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect | Exploitation statusNot known exploited | FixYes | Published07/01/2024 | SeverityCritical |
CVE-2024-38475Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path. | Exploitation statusKEV | FixYes | Published07/01/2024 | SeverityCritical |
CVE-2024-38474Apache HTTP Server weakness with encoded question marks in backreferences | Exploitation statusNot known exploited | FixYes | Published07/01/2024 | SeverityHigh |
CVE-2024-38473Apache HTTP Server proxy encoding problem | Exploitation statusNot known exploited | FixYes | Published07/01/2024 | SeverityHigh |
CVE-2024-38472Apache HTTP Server on WIndows UNC SSRF | Exploitation statusNot known exploited | FixYes | Published07/01/2024 | SeverityHigh |
CVE-2024-36387Apache HTTP Server: DoS by Null pointer in websocket over HTTP/2 | Exploitation statusNot known exploited | FixYes | Published07/01/2024 | SeverityMedium |
CVE-2024-27316Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames | Exploitation statusNot known exploited | FixYes | Published04/04/2024 | SeverityHigh |
CVE-2024-24795Apache HTTP Server: HTTP Response Splitting in multiple modules | Exploitation statusNot known exploited | FixYes | Published04/04/2024 | SeverityMedium |
CVE-2023-38709Apache HTTP Server: HTTP response splitting | Exploitation statusNot known exploited | FixYes | Published04/04/2024 | SeverityHigh |
CVE-2023-31122Apache HTTP Server: mod_macro buffer over-read | Exploitation statusNot known exploited | FixYes | Published10/23/2023 | SeverityUnknown |
CVE-2023-43622Apache HTTP Server: DoS in HTTP/2 with initial windows size 0 | Exploitation statusPublic exploit | FixYes | Published10/23/2023 | SeverityUnknown |
CVE-2023-45802Apache HTTP Server: HTTP/2 stream memory not reclaimed right away on RST | Exploitation statusNot known exploited | FixYes | Published10/23/2023 | SeverityUnknown |
CVE-2023-27522Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting | Exploitation statusNot known exploited | FixYes | Published03/07/2023 | SeverityHigh |
CVE-2023-25690Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy | Exploitation statusPublic exploit | FixNot confirmed | Published03/07/2023 | SeverityCritical |
CVE-2022-37436Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting | Exploitation statusNot known exploited | FixYes | Published01/17/2023 | SeverityMedium |
CVE-2022-36760Apache HTTP Server: mod_proxy_ajp Possible request smuggling | Exploitation statusNot known exploited | FixYes | Published01/17/2023 | SeverityCritical |
CVE-2006-20001Apache HTTP Server: mod_dav out of bounds read, or write of zero byte | Exploitation statusNot known exploited | FixYes | Published01/17/2023 | SeverityUnknown |
CVE-2022-31813mod_proxy X-Forwarded-For dropped by hop-by-hop mechanism | Exploitation statusNot confirmed | FixNot confirmed | Published06/08/2022 | SeverityUnknown |
CVE-2022-30556Information Disclosure in mod_lua with websockets | Exploitation statusNot confirmed | FixNot confirmed | Published06/08/2022 | SeverityUnknown |
CVE-2022-30522mod_sed denial of service | Exploitation statusNot confirmed | FixNot confirmed | Published06/08/2022 | SeverityUnknown |
CVE-2022-29404Denial of service in mod_lua r:parsebody | Exploitation statusNot confirmed | FixNot confirmed | Published06/08/2022 | SeverityUnknown |
CVE-2022-28615Read beyond bounds in ap_strcmp_match() | Exploitation statusNot known exploited | FixNot confirmed | Published06/08/2022 | SeverityCritical |
CVE-2022-28614read beyond bounds via ap_rwrite() | Exploitation statusNot confirmed | FixNot confirmed | Published06/08/2022 | SeverityUnknown |
CVE-2022-28330read beyond bounds in mod_isapi | Exploitation statusNot confirmed | FixNot confirmed | Published06/08/2022 | SeverityUnknown |
CVE-2022-26377mod_proxy_ajp: Possible request smuggling | Exploitation statusNot confirmed | FixNot confirmed | Published06/08/2022 | SeverityUnknown |
CVE-2022-23943mod_sed: Read/write beyond bounds | Exploitation statusNot confirmed | FixNot confirmed | Published03/14/2022 | SeverityUnknown |
CVE-2022-22721core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody | Exploitation statusNot confirmed | FixNot confirmed | Published03/14/2022 | SeverityUnknown |
CVE-2022-22720HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier | Exploitation statusNot confirmed | FixNot confirmed | Published03/14/2022 | SeverityUnknown |
CVE-2022-22719mod_lua Use of uninitialized value of in r:parsebody | Exploitation statusNot confirmed | FixNot confirmed | Published03/14/2022 | SeverityUnknown |
CVE-2021-44224Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlier | Exploitation statusNot confirmed | FixYes | Published12/20/2021 | SeverityUnknown |
CVE-2021-44790Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier | Exploitation statusNot confirmed | FixYes | Published12/20/2021 | SeverityUnknown |
CVE-2021-42013Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773) | Exploitation statusKEV | FixNot confirmed | Published10/07/2021 | SeverityCritical |
CVE-2021-41773Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 | Exploitation statusKEV | FixYes | Published10/05/2021 | SeverityHigh |
CVE-2021-41524null pointer dereference in h2 fuzzing | Exploitation statusNot confirmed | FixYes | Published10/05/2021 | SeverityUnknown |
CVE-2021-40438mod_proxy SSRF | Exploitation statusKEV | FixNot confirmed | Published09/16/2021 | SeverityCritical |
CVE-2021-39275ap_escape_quotes buffer overflow | Exploitation statusNot confirmed | FixNot confirmed | Published09/16/2021 | SeverityUnknown |
CVE-2021-36160mod_proxy_uwsgi out of bound read | Exploitation statusNot confirmed | FixNot confirmed | Published09/16/2021 | SeverityUnknown |
CVE-2021-34798NULL pointer dereference in httpd core | Exploitation statusNot confirmed | FixNot confirmed | Published09/16/2021 | SeverityUnknown |
CVE-2021-33193Request splitting via HTTP/2 method injection and mod_proxy | Exploitation statusNot confirmed | FixNot confirmed | Published08/16/2021 | SeverityUnknown |
CVE-2021-31618NULL pointer dereference on specially crafted HTTP/2 request | Exploitation statusNot known exploited | FixNot confirmed | Published06/15/2021 | SeverityUnknown |
CVE-2021-30641Unexpected URL matching with 'MergeSlashes OFF' | Exploitation statusNot confirmed | FixNot confirmed | Published06/10/2021 | SeverityUnknown |
CVE-2021-26691Apache HTTP Server mod_session response handling heap overflow | Exploitation statusNot confirmed | FixNot confirmed | Published06/10/2021 | SeverityUnknown |
CVE-2021-26690mod_session NULL pointer dereference | Exploitation statusNot confirmed | FixNot confirmed | Published06/10/2021 | SeverityUnknown |
CVE-2020-35452mod_auth_digest possible stack overflow by one nul byte | Exploitation statusNot confirmed | FixNot confirmed | Published06/10/2021 | SeverityUnknown |
CVE-2020-13950mod_proxy_http NULL pointer dereference | Exploitation statusNot confirmed | FixNot confirmed | Published06/10/2021 | SeverityUnknown |
CVE-2020-13938Improper Handling of Insufficient Privileges | Exploitation statusNot confirmed | FixNot confirmed | Published06/10/2021 | SeverityUnknown |
CVE-2019-17567mod_proxy_wstunnel tunneling of non Upgraded connections | Exploitation statusNot confirmed | FixNot confirmed | Published06/10/2021 | SeverityUnknown |
CVE-2019-0197 | Exploitation statusNot confirmed | FixNot confirmed | Published06/11/2019 | SeverityUnknown |
CVE-2019-0196 | Exploitation statusNot confirmed | FixNot confirmed | Published06/11/2019 | SeverityUnknown |
CVE-2019-0220 | Exploitation statusNot confirmed | FixNot confirmed | Published06/11/2019 | SeverityUnknown |
CVE-2018-17189 | Exploitation statusNot confirmed | FixNot confirmed | Published01/30/2019 | SeverityUnknown |
CVE-2018-17199 | Exploitation statusNot confirmed | FixNot confirmed | Published01/30/2019 | SeverityUnknown |
CVE-2019-0190 | Exploitation statusNot confirmed | FixNot confirmed | Published01/30/2019 | SeverityUnknown |
CVE-2018-11763 | Exploitation statusNot confirmed | FixNot confirmed | Published09/25/2018 | SeverityUnknown |
CVE-2016-4975mod_userdir CRLF injection | Exploitation statusNot confirmed | FixYes | Published08/14/2018 | SeverityUnknown |
CVE-2018-8011mod_md, DoS via Coredumps on specially crafted requests | Exploitation statusNot confirmed | FixYes | Published07/18/2018 | SeverityUnknown |
CVE-2018-1333DoS for HTTP/2 connections by crafted requests | Exploitation statusNot confirmed | FixYes | Published06/18/2018 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan