CVE-2022-22719high · CVSS 7.5 — A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache
CVE-2022-22720critical · CVSS 9.8 — Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing th
CVE-2022-22721critical · CVSS 9.1 — If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which
CVE-2022-23943critical · CVSS 9.8 — Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provid
CVE-2022-26377high · CVSS 7.5 — Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attac
CVE-2022-28330medium · CVSS 5.3 — Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.
CVE-2022-28614medium · CVSS 5.3 — The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect
CVE-2022-28615critical · CVSS 9.1 — Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with
CVE-2022-29404high · CVSS 7.5 — In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to
CVE-2022-30556high · CVSS 7.5 — Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated
CVE-2022-31813critical · CVSS 9.8 — Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop
CVE-2006-20001high · CVSS 7.5 — A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the
CVE-2022-36760critical · CVSS 9.0 — Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attac
CVE-2022-37436medium · CVSS 5.3 — Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers bein
CVE-2023-25690critical · CVSS 9.8 — Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack.
Configurations
CVE-2023-27522high · CVSS 7.5 — HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through
CVE-2023-31122high · CVSS 7.5 — Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.
CVE-2023-45802medium · CVSS 5.9 — When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were not reclaimed immed
CVE-2023-38709high · CVSS 7.3 — Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses.
This issu
CVE-2024-24795medium · CVSS 6.3 — HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend
CVE-2024-27316high · CVSS 7.5 — HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a
CVE-2024-38472high · CVSS 7.5 — SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or conten
CVE-2024-38473high · CVSS 8.1 — Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend ser
CVE-2024-38474critical · CVSS 9.8 — Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in
directories permit
CVE-2024-38475critical · CVSS 9.1 — Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations t
CVE-2024-38476critical · CVSS 9.8 — Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via
CVE-2024-38477high · CVSS 7.5 — null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious reques
CVE-2024-39573high · CVSS 7.5 — Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup
CVE-2024-40898high · CVSS 7.5 — SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server
CVE-2024-42516high · CVSS 7.5 — HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applica
CVE-2024-43204high · CVSS 7.5 — SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker. Re
CVE-2024-43394high · CVSS 7.5 — Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via
mod_re
CVE-2024-47252high · CVSS 7.5 — Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert
CVE-2025-23048critical · CVSS 9.1 — In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using
CVE-2025-49630high · CVSS 7.5 — In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by
CVE-2025-49812high · CVSS 7.4 — In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle
CVE-2025-53020high · CVSS 7.5 — Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: from 2.4.17 up
CVE-2025-55753high · CVSS 7.5 — An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), t
CVE-2025-59775high · CVSS 7.5 — Server-Side Request Forgery (SSRF) vulnerability
in Apache HTTP Server on Windows
with AllowEncodedSlashes On and MergeSlashes Off all
CVE-2025-65082medium · CVSS 6.5 — Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the
CVE-2025-66200medium · CVSS 5.4 — mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directi
CVE-2025-58098high · CVSS 8.3 — Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query
CVE-2026-24072high · CVSS 8.8 — An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the pr
CVE-2026-34059high · CVSS 7.5 — Buffer Over-read vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgr
CVE-2026-33857medium · CVSS 5.3 — Out-of-bounds Read vulnerability in mod_proxy_ajp of
Apache HTTP Server.
This issue affects Apache HTTP Server: through 2.4.66.
Users ar
CVE-2026-34032medium · CVSS 5.3 — Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: through 2.4.66.
CVE-2026-29169high · CVSS 7.5 — A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicio
CVE-2026-33006medium · CVSS 4.8 — A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker.
Users a
CVE-2026-33007medium · CVSS 5.3 — A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash
CVE-2026-33523medium · CVSS 6.5 — HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers.
This issue affe