CVEs (330)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where...Show more |
2Apache Netapp2Http Server Ontap ToolsJun 17, 2026 Jul 4, 2024 N/A· v4 6.2 MEDIUM· v3 N/A· v2 A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested...Show more |
Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users are recommended to upgrade to version 2...Show more |
2Apache Netapp2Clustered Data Ontap Http ServerJun 17, 2026 Jul 1, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request.
Users are recommended to upgrade to version 2.4.60, which fixes this issue. |
2Apache Netapp2Clustered Data Ontap Http ServerJun 17, 2026 Jul 1, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users...Show more |
3Apache NetappSonicwall7Http Server Ontap 9Sma 200 Firmware+4 moreJun 17, 2026 Jul 1, 2024 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly...Show more |
2Apache Netapp2Clustered Data Ontap Http ServerJun 17, 2026 Jul 1, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclos...Show more |
Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are reco...Show more |
SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue. N...Show more |
Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance. |
3Apache FedoraprojectNetapp3Fedora Http ServerOntapJun 17, 2026 Apr 4, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion. |
6Apache AppleBroadcom+3 more7Debian Linux Fabric Operating SystemFedora+4 moreJun 17, 2026 Apr 4, 2024 N/A· v4 6.3 MEDIUM· v3 N/A· v2 HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended...Show more |
6Apache AppleBroadcom+3 more7Debian Linux Fabric Operating SystemFedora+4 moreJun 17, 2026 Apr 4, 2024 N/A· v4 7.3 HIGH· v3 N/A· v2 Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses.
This issue affects Apache HTTP Server: through 2.4.58. |
3Apache DebianFedoraproject3Debian Linux FedoraHttp ServerJun 17, 2026 Oct 23, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were not reclaimed immediately. Instead, de-allocation was deferred to connection close. A client could...Show more |
An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resources in the server, s...Show more |
3Apache DebianFedoraproject3Debian Linux FedoraHttp ServerJun 17, 2026 Oct 23, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57. |
3Apache DebianUnbit3Debian Linux Http ServerUwsgiJun 17, 2026 Mar 7, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the...Show more |
Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or P...Show more |
Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security pu...Show more |
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue a...Show more |