Apache

HTTP Server

306 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 90.49%
  • Veröffentlicht 01.07.2024 19:15:04
  • Zuletzt bearbeitet 01.07.2025 20:24:46

SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue.  Note: Existing configurations t...

  • EPSS 88.26%
  • Veröffentlicht 01.07.2024 19:15:04
  • Zuletzt bearbeitet 01.07.2025 20:25:09

Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version ...

  • EPSS 0.59%
  • Veröffentlicht 01.07.2024 19:15:04
  • Zuletzt bearbeitet 25.03.2025 19:15:43

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only t...

Warnung Medienbericht
  • EPSS 93.86%
  • Veröffentlicht 01.07.2024 19:15:04
  • Zuletzt bearbeitet 17.11.2025 21:49:55

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resultin...

  • EPSS 3.45%
  • Veröffentlicht 01.07.2024 19:15:04
  • Zuletzt bearbeitet 03.11.2025 22:17:01

Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to...

  • EPSS 0.14%
  • Veröffentlicht 01.07.2024 19:15:03
  • Zuletzt bearbeitet 06.11.2025 22:26:05

Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.

  • EPSS 3.26%
  • Veröffentlicht 04.04.2024 20:15:08
  • Zuletzt bearbeitet 04.11.2025 22:15:53

Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.

  • EPSS 1.12%
  • Veröffentlicht 04.04.2024 20:15:08
  • Zuletzt bearbeitet 30.06.2025 12:55:47

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, ...

  • EPSS 89.12%
  • Veröffentlicht 04.04.2024 20:15:08
  • Zuletzt bearbeitet 04.11.2025 22:15:59

HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.

  • EPSS 0.4%
  • Veröffentlicht 23.10.2023 07:15:11
  • Zuletzt bearbeitet 01.08.2025 02:03:27

Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.