Apache
Apache Http Server: vulnerabilidades y CVE
Apache Http Server tiene 339 vulnerabilidades publicadas, 35 de ellas en los últimos 12 meses. 33 son críticas y 5 figuran en el catálogo de explotación activa de CISA.
CVE339
Últimos 12 meses35
Críticas33
Explotadas activamente5
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-38475 | Crítica (9.1) | 100% | ⚠ Explotación activa | 1 jul 2024 | Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly… |
| CVE-2021-40438 | Crítica (9) | 100% | ⚠ Explotación activa | 16 sept 2021 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. |
| CVE-2021-42013 | Crítica (9.8) | 100% | ⚠ Explotación activa | 7 oct 2021 | It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives.… |
| CVE-2021-41773 | Crítica (9.8) | 100% | ⚠ Explotación activa | 5 oct 2021 | A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If… |
| CVE-2019-0211 | Alta (7.8) | 65% | ⚠ Explotación activa | 8 abr 2019 | In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter)… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-89282 | Crítica (9.1) | 0.27% | — | 22 sept 2026 | The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissions vulnerability through its default install directory on C:\, which inherits write access for… |
| CVE-2026-89281 | Alta (8.4) | 0.13% | — | 22 sept 2026 | The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability within openssl.cnf path that can allow local code execution. |
| CVE-2026-90937 | Crítica (9.4) | 0.45% | — | 14 sept 2026 | froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs… |
| CVE-2026-54789 | Alta (7.5) | 0.72% | — | 21 ago 2026 | mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and… |
| CVE-2026-67178 | Alta (7.8) | 0.66% | — | 28 jul 2026 | MISP installation scripts generated an Apache HTTP virtual-host configuration containing an incorrectly formatted HTTP-to-HTTPS redirect: Redirect permanent / https://misp.example Apache’s Redirect directive appends any… |
| CVE-2026-23697 | Alta (8.7) | 1.00% | — | 7 jul 2026 | Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code through the Documents… |
| CVE-2026-49975 | Alta (7.5) | 4.2% | — | 8 jun 2026 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. |
| CVE-2026-48913 | Alta (7.3) | 1.1% | — | 8 jun 2026 | Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67. |
| CVE-2026-44631 | Crítica (9.8) | 0.75% | — | 8 jun 2026 | Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version… |
| CVE-2026-44186 | Alta (7.3) | 1.1% | — | 8 jun 2026 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue affects undefined: from 2.4.0 through… |
| CVE-2026-44185 | Alta (7.3) | 1.8% | — | 8 jun 2026 | Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to… |
| CVE-2026-44119 | Media (5.5) | 0.29% | — | 8 jun 2026 | Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. This issue affects Apache HTTP Server: from… |
| CVE-2026-43951 | Media (6.5) | 1.0% | — | 8 jun 2026 | Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. |
| CVE-2026-42536 | Alta (7.5) | 2.7% | — | 8 jun 2026 | Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade… |
| CVE-2026-42535 | Crítica (9.1) | 0.71% | — | 8 jun 2026 | A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to… |
| CVE-2026-34356 | Alta (7.5) | 1.2% | — | 8 jun 2026 | Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to… |
| CVE-2026-34355 | Alta (7.5) | 2.7% | — | 8 jun 2026 | A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue. |
| CVE-2026-29170 | Media (6.1) | 1.0% | — | 8 jun 2026 | A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy… |
| CVE-2026-29167 | Crítica (9.8) | 0.95% | — | 8 jun 2026 | Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which… |
| CVE-2026-28780 | Crítica (9.8) | 1.6% | — | 5 may 2026 | Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to… |
| CVE-2026-29168 | Alta (7.3) | 1.1% | — | 5 may 2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to… |
| CVE-2026-33523 | Media (6.5) | 0.44% | — | 4 may 2026 | HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP Server: from through 2.4.66. Users are recommended to upgrade to… |
| CVE-2026-33007 | Media (5.3) | 1.2% | — | 4 may 2026 | A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration. Users are recommended… |
| CVE-2026-33006 | Media (4.8) | 0.56% | — | 4 may 2026 | A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade to version 2.4.67, which fixes this issue. |
| CVE-2026-29169 | Alta (7.5) | 1.6% | — | 4 may 2026 | A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The… |
| CVE-2026-23918 | Alta (8.8) | 50% | — | 4 may 2026 | Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. |
| CVE-2026-34032 | Media (5.3) | 0.94% | — | 4 may 2026 | Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. |
| CVE-2026-33857 | Media (5.3) | 0.94% | — | 4 may 2026 | Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. |
| CVE-2026-34059 | Alta (7.5) | 0.95% | — | 4 may 2026 | Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. |
| CVE-2026-24072 | Alta (8.8) | 0.65% | — | 4 may 2026 | An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67,… |