apache / http_server
15 known vulnerabilities in apache http_server.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-40438 | Act now | 100.0% | 9.0 | ● | A crafted request uri-path can cause mod_proxy to forward the request to an orig… |
| CVE-2026-49975 | Medium | 34.3% | 7.5 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server'… | |
| CVE-2026-28780 | Medium | 1.4% | 9.8 | Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.… | |
| CVE-2026-34355 | Medium | 1.2% | 7.5 | A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier all… | |
| CVE-2026-42536 | Medium | 1.0% | 7.5 | Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc,… | |
| CVE-2026-44185 | Medium | 0.7% | 7.3 | Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests … | |
| CVE-2026-34356 | Medium | 0.7% | 7.5 | Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious ba… | |
| CVE-2026-29167 | Medium | 0.7% | 9.8 | Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-director… | |
| CVE-2026-44186 | Medium | 0.6% | 7.3 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_… | |
| CVE-2026-42535 | Medium | 0.5% | 9.1 | A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV… | |
| CVE-2026-44631 | Medium | 0.5% | 9.8 | Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular express… | |
| CVE-2026-48913 | Medium | 0.5% | 7.3 | Use After Free vulnerability in Apache HTTP Server module mod_http2 when file ha… | |
| CVE-2026-43951 | Low | 0.5% | 6.5 | Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_… | |
| CVE-2026-29170 | Low | 0.5% | 6.1 | A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory li… | |
| CVE-2026-44119 | Low | 0.2% | 5.5 | Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and ear… |