Apache Http Server

Apache · 144 CVEs

CVE-2026-93546
HIGH

Apache HTTP Server: mod_dav_fs namespace overflow

Oct 1, 2026

CVE-2026-79768
MEDIUM

Apache HTTP Server: mod_userdir information disclosure

Oct 1, 2026

CVE-2026-73637
HIGH

Apache HTTP Server: mod_auth_digest DoS attack

Oct 1, 2026

CVE-2026-73636
HIGH

Apache HTTP Server: mod_auth_digest one-time-nonce replay attack

Oct 1, 2026

CVE-2026-63686
HIGH

Apache HTTP Server: mod_xml2enc crash on charset conversion failure

Oct 1, 2026

CVE-2026-63292
HIGH

Apache HTTP Server: mod_vhost_alias stack overflow

Oct 1, 2026

CVE-2026-63045
HIGH

Apache HTTP Server: mod_proxy_ftp PASV address handling

Oct 1, 2026

CVE-2026-59797
CRITICAL

Apache HTTP Server: mod_ssl SSLRequire allows .htaccess ap_expr file-function

Oct 1, 2026

CVE-2026-59685
HIGH

Apache HTTP Server: Out-of-Bounds Write in ap_directory_walk() Canonical-Name Rewrite on CASE_BLIND_FILESYSTEM

Oct 1, 2026

CVE-2026-58415
MEDIUM

Apache HTTP Server: mod_dav_fs property database read access

Oct 1, 2026

CVE-2026-57941
CRITICAL

Apache HTTP Server: mod_http2 use-after-free / wild write via shared session->bbtmp re-entrancy

Oct 1, 2026

CVE-2026-56449
HIGH

Apache HTTP Server: mod_proxy_html: crash in dump_content

Oct 1, 2026

CVE-2026-56154
CRITICAL

Apache HTTP Server: mod_rewrite use-after-free via %{LA-U:HTTP:...}

Oct 1, 2026

CVE-2026-56153
HIGH

Apache HTTP Server: mod_charset_lite: Heap overflow in finish_partial_char

Oct 1, 2026

CVE-2026-48005
HIGH

Apache HTTP Server: mod_auth_digest reauthentication attack

Oct 1, 2026

CVE-2026-47360
HIGH

Apache HTTP Server: mod_session: Session cookie not removed during internal redirect

Oct 1, 2026

CVE-2026-46729
HIGH

Apache HTTP Server: mod_heartmonitor denial of service

Oct 1, 2026

CVE-2026-42528
MEDIUM

Apache HTTP Server: mod_dav shared lock overflow

Oct 1, 2026

CVE-2026-42356
LOW

Apache HTTP Server: limited RCE for some internal redirects to non-CGI files in CGI directories

Oct 1, 2026

CVE-2026-63718
HIGH

Apache HTTP Server: mod_proxy_uwsgi Transfer-Encoding response smuggling

Oct 1, 2026

CVE-2026-49975
HIGH

Apache HTTP Server: mod_http2 denial of service

Jun 8, 2026

CVE-2026-48913
HIGH

Apache HTTP Server: mod_http2 memory corruption when file handles exhausted

Jun 8, 2026

CVE-2026-42536
HIGH

Apache HTTP Server: mod_xml2enc heap overflow

Jun 8, 2026

CVE-2026-44185
HIGH

Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request`

Jun 8, 2026

CVE-2026-34355
HIGH

Apache HTTP Server: mod_proxy_html buffer overflow

Jun 8, 2026

Showing 1 to 25 of 144 CVEs