Back

LOW

Apache HTTP Server: limited RCE for some internal redirects to non-CGI files in CGI directories

Published Oct 1, 2026

Description

Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime.

This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Oct 1, 2026
Updated Oct 1, 2026
Reserved Apr 26, 2026
CISA Vulnrichment
Updated Oct 1, 2026
NVD
Status Received
Modified Oct 1, 2026
Red Hat
Severity n/a
Public date n/a