Apache / Apache Http Server
144 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-63686 | Apache HTTP Server: mod_xml2enc crash on charset conversion failure | HIGH | 7.5 | Oct 1, 2026 |
| CVE-2026-93546 | Apache HTTP Server: mod_dav_fs namespace overflow | HIGH | 8.8 | Oct 1, 2026 |
| CVE-2026-79768 | Apache HTTP Server: mod_userdir information disclosure | MEDIUM | 5.3 | Oct 1, 2026 |
| CVE-2026-73637 | Apache HTTP Server: mod_auth_digest DoS attack | HIGH | 7.3 | Oct 1, 2026 |
| CVE-2026-73636 | Apache HTTP Server: mod_auth_digest one-time-nonce replay attack | HIGH | 8.1 | Oct 1, 2026 |
| CVE-2026-63718 | Apache HTTP Server: mod_proxy_uwsgi Transfer-Encoding response smuggling | HIGH | 7.5 | Oct 1, 2026 |
| CVE-2026-63292 | Apache HTTP Server: mod_vhost_alias stack overflow | HIGH | 7.5 | Oct 1, 2026 |
| CVE-2026-63045 | Apache HTTP Server: mod_proxy_ftp PASV address handling | HIGH | 7.5 | Oct 1, 2026 |
| CVE-2026-59797 | Apache HTTP Server: mod_ssl SSLRequire allows .htaccess ap_expr file-function | CRITICAL | 9.8 | Oct 1, 2026 |
| CVE-2026-59685 | Apache HTTP Server: Out-of-Bounds Write in ap_directory_walk() Canonical-Name Rewrite on CASE_BLIND_FILESYSTEM | HIGH | 7.5 | Oct 1, 2026 |
| CVE-2026-58415 | Apache HTTP Server: mod_dav_fs property database read access | MEDIUM | 5.3 | Oct 1, 2026 |
| CVE-2026-57941 | Apache HTTP Server: mod_http2 use-after-free / wild write via shared session->bbtmp re-entrancy | CRITICAL | 9.8 | Oct 1, 2026 |
| CVE-2026-56449 | Apache HTTP Server: mod_proxy_html: crash in dump_content | HIGH | 7.5 | Oct 1, 2026 |
| CVE-2026-56154 | Apache HTTP Server: mod_rewrite use-after-free via %{LA-U:HTTP:...} | CRITICAL | 9.8 | Oct 1, 2026 |
| CVE-2026-56153 | Apache HTTP Server: mod_charset_lite: Heap overflow in finish_partial_char | HIGH | 7.5 | Oct 1, 2026 |
| CVE-2026-48005 | Apache HTTP Server: mod_auth_digest reauthentication attack | HIGH | 7.5 | Oct 1, 2026 |
| CVE-2026-47360 | Apache HTTP Server: mod_session: Session cookie not removed during internal redirect | HIGH | 7.5 | Oct 1, 2026 |
| CVE-2026-46729 | Apache HTTP Server: mod_heartmonitor denial of service | HIGH | 7.5 | Oct 1, 2026 |
| CVE-2026-42356 | Apache HTTP Server: limited RCE for some internal redirects to non-CGI files in CGI directories | LOW | 3.7 | Oct 1, 2026 |
| CVE-2026-42528 | Apache HTTP Server: mod_dav shared lock overflow | MEDIUM | 4.3 | Oct 1, 2026 |
| CVE-2026-49975 | Apache HTTP Server: mod_http2 denial of service | HIGH | 7.5 | Jun 8, 2026 |
| CVE-2026-48913 | Apache HTTP Server: mod_http2 memory corruption when file handles exhausted | HIGH | 7.3 | Jun 8, 2026 |
| CVE-2026-42536 | Apache HTTP Server: mod_xml2enc heap overflow | HIGH | 7.5 | Jun 8, 2026 |
| CVE-2026-44185 | Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request` | HIGH | 7.3 | Jun 8, 2026 |
| CVE-2026-34355 | Apache HTTP Server: mod_proxy_html buffer overflow | HIGH | 7.5 | Jun 8, 2026 |
Showing 1 to 25 of 144 CVEs