VendorsApachehttp_serverany version
Vulnerabilities

Apache HTTP Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

217CVEs
CVE-2010-0425
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."
Published 2010-03-05 · Analyzed
10.02 PoCEPSS 0.942
CVE-2005-2700
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
Published 2005-09-06 · Modified
10.0EPSS 0.306
CVE-2003-0789
mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.
Published 2003-10-30 · Modified
10.0EPSS 0.124
CVE-1999-1237
Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified methods.
Published 2001-09-12 · Modified
10.0EPSS 0.081
CVE-1999-1199
Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the "sioux" vulnerability.
Published 2004-09-01 · Modified
10.0EPSS 0.076
CVE-1999-1293
mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.
Published 2001-09-12 · Modified
10.0EPSS 0.040
CVE-2021-44790
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
Published 2021-12-20 · Analyzed
9.81 PoCEPSS 0.968
CVE-2020-11984
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
Published 2020-08-07 · Modified
9.8EPSS 0.900
CVE-2009-3555
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
Published 2009-11-09 · Modified
9.82 PoCEPSS 0.873
CVE-2023-25690
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
Published 2023-03-07 · Modified
9.8EPSS 0.845
CVE-2021-26691
Apache HTTP Server mod_session response handling heap overflow
Published 2021-06-10 · Modified
9.8EPSS 0.683
CVE-2022-23943
mod_sed: Read/write beyond bounds
Published 2022-03-14 · Analyzed
9.8EPSS 0.504
CVE-2024-38476
Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect
Published 2024-07-01 · Modified
9.8EPSS 0.416
CVE-2021-39275
ap_escape_quotes buffer overflow
Published 2021-09-16 · Analyzed
9.8EPSS 0.394
CVE-2017-7679
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header.
Published 2017-06-20 · Modified
9.8EPSS 0.393
CVE-2022-22720
HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier
Published 2022-03-14 · Modified
9.8EPSS 0.282
CVE-2017-3167
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed.
Published 2017-06-20 · Modified
9.8EPSS 0.202
CVE-2022-31813
mod_proxy X-Forwarded-For dropped by hop-by-hop mechanism
Published 2022-06-08 · Analyzed
9.8EPSS 0.035
CVE-2024-38474
Apache HTTP Server weakness with encoded question marks in backreferences
Published 2024-07-01 · Modified
9.8EPSS 0.025
CVE-2026-28780
Apache HTTP Server: buffer overflow in mod_proxy_ajp via ajp_msg_check_header()
Published 2026-05-05 · Modified
9.8EPSS 0.014
CVE-2026-29167
Apache HTTP Server: mod_ldap per-dir use-after-free
Published 2026-06-08 · Analyzed
9.8EPSS 0.007
CVE-2026-44631
Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow
Published 2026-06-08 · Analyzed
9.8EPSS 0.005
CVE-2024-38475
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
Published 2024-07-01 · Analyzed
9.1KEVEPSS 1.000
CVE-2017-9788
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest. Providing an initial key with no '=' assignment could reflect the stale value of uninitialized pool memory used by the prior request, leading to leakage of potentially confidential information, and a segfault in other cases resulting in denial of service.
Published 2017-07-13 · Modified
9.1EPSS 0.568
CVE-2022-22721
core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody
Published 2022-03-14 · Modified
9.1EPSS 0.417
CVE-2019-10082
In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during connection shutdown.
Published 2019-09-26 · Modified
9.1EPSS 0.165
CVE-2022-28615
Read beyond bounds in ap_strcmp_match()
Published 2022-06-08 · Modified
9.1EPSS 0.063
CVE-2024-40898
Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows
Published 2024-07-18 · Modified
9.1EPSS 0.015
CVE-2025-23048
Apache HTTP Server: mod_ssl access control bypass with session resumption
Published 2025-07-10 · Modified
9.1EPSS 0.010
CVE-2026-42535
Apache HTTP Server: mod_dav_fs protected directory access
Published 2026-06-08 · Analyzed
9.1EPSS 0.005
CVE-2021-40438
mod_proxy SSRF
Published 2021-09-16 · Analyzed
9.0KEVEPSS 1.000
CVE-2022-36760
Apache HTTP Server: mod_proxy_ajp Possible request smuggling
Published 2023-01-17 · Modified
9.0EPSS 0.019
CVE-2026-24072
Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr
Published 2026-05-04 · Analyzed
8.8EPSS 0.007
CVE-2025-58098
Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...
Published 2025-12-05 · Analyzed
8.3EPSS 0.014
CVE-2021-44224
Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlier
Published 2021-12-20 · Modified
8.2EPSS 0.823
CVE-2017-15715
In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in environments where uploads of some files are are externally blocked, but only by matching the trailing portion of the filename.
Published 2018-03-26 · Modified
8.1EPSS 0.855
CVE-2016-5387
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability.
Published 2016-07-19 · Modified
8.1EPSS 0.557
CVE-2024-38473
Apache HTTP Server proxy encoding problem
Published 2024-07-01 · Analyzed
8.1EPSS 0.259
CVE-2011-3192
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
Published 2011-08-29 · Modified
7.82 PoCEPSS 0.988
CVE-2019-0211
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
Published 2019-04-08 · Analyzed
7.8KEV1 PoCEPSS 0.650
1 / 6Next →