CVE-2026-58415
- EPSS 0.3%
- Veröffentlicht 01.10.2026 16:07:20
- Zuletzt bearbeitet 05.10.2026 13:22:10
Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request fo...
CVE-2026-57941
- EPSS 0.44%
- Veröffentlicht 01.10.2026 16:06:53
- Zuletzt bearbeitet 05.10.2026 13:29:16
Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
CVE-2026-56449
- EPSS 0.42%
- Veröffentlicht 01.10.2026 16:06:24
- Zuletzt bearbeitet 05.10.2026 13:29:51
Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
CVE-2026-56154
- EPSS 0.42%
- Veröffentlicht 01.10.2026 16:03:52
- Zuletzt bearbeitet 05.10.2026 13:33:38
Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
CVE-2026-56153
- EPSS 0.5%
- Veröffentlicht 01.10.2026 16:03:25
- Zuletzt bearbeitet 02.10.2026 20:53:53
Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
CVE-2026-48005
- EPSS 0.61%
- Veröffentlicht 01.10.2026 16:01:35
- Zuletzt bearbeitet 06.10.2026 14:07:10
Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization ...
CVE-2026-47360
- EPSS 0.39%
- Veröffentlicht 01.10.2026 16:00:51
- Zuletzt bearbeitet 02.10.2026 20:57:52
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module. When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server....
CVE-2026-46729
- EPSS 0.47%
- Veröffentlicht 01.10.2026 15:55:27
- Zuletzt bearbeitet 02.10.2026 21:00:58
NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
CVE-2026-42356
- EPSS 0.47%
- Veröffentlicht 01.10.2026 15:54:35
- Zuletzt bearbeitet 06.10.2026 14:07:21
Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extensi...
CVE-2026-42528
- EPSS 0.42%
- Veröffentlicht 01.10.2026 15:52:51
- Zuletzt bearbeitet 06.10.2026 14:07:28
A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes. Users are recommended to upgrade to version 2.4.69, which fixes this issue