Apache

HTTP Server

302 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.48%
  • Veröffentlicht 29.04.2025 11:56:50
  • Zuletzt bearbeitet 28.07.2025 14:15:27

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes c...

  • EPSS 0.47%
  • Veröffentlicht 18.07.2024 10:15:03
  • Zuletzt bearbeitet 21.11.2024 09:31:48

SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue. 

  • EPSS 21.38%
  • Veröffentlicht 18.07.2024 10:15:02
  • Zuletzt bearbeitet 14.03.2025 18:15:29

A partial fix for  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly...

  • EPSS 0.27%
  • Veröffentlicht 04.07.2024 09:15:04
  • Zuletzt bearbeitet 01.07.2025 20:27:13

A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers.   "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source ...

  • EPSS 0.92%
  • Veröffentlicht 01.07.2024 19:15:05
  • Zuletzt bearbeitet 03.11.2025 22:17:01

null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

  • EPSS 2.59%
  • Veröffentlicht 01.07.2024 19:15:05
  • Zuletzt bearbeitet 03.11.2025 22:17:06

Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

  • EPSS 90.49%
  • Veröffentlicht 01.07.2024 19:15:04
  • Zuletzt bearbeitet 01.07.2025 20:24:46

SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue.  Note: Existing configurations t...

  • EPSS 87.86%
  • Veröffentlicht 01.07.2024 19:15:04
  • Zuletzt bearbeitet 01.07.2025 20:25:09

Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version ...

  • EPSS 0.61%
  • Veröffentlicht 01.07.2024 19:15:04
  • Zuletzt bearbeitet 25.03.2025 19:15:43

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only t...

Warnung Medienbericht
  • EPSS 93.86%
  • Veröffentlicht 01.07.2024 19:15:04
  • Zuletzt bearbeitet 17.11.2025 21:49:55

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resultin...