3.7
CVE-2026-42356
- EPSS 0.47%
- Veröffentlicht 01.10.2026 15:54:35
- Zuletzt bearbeitet 06.10.2026 14:07:21
- Erkennungen
Apache HTTP Server: limited RCE for some internal redirects to non-CGI files in CGI directories
Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ HTTP Server Version >= 2.4.0 < 2.4.69
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.47% | 0.384 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 3.7 | 2.2 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
|
CWE-430 Deployment of Wrong Handler
The wrong "handler" is assigned to process an object.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://httpd.apache.org/security/vulnerabilities_24.html
http://www.openwall.com/lists/oss-security/2026/10/01/11