Known Vulnerabilities for Apache HTTP Server by Apache Software Foundation
Listed below are 10 of the newest known vulnerabilities associated with "Apache HTTP Server" by "Apache Software Foundation".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-49975 json | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via mal... | Not Provided | 2026-06-08 | 2026-06-18 |
| CVE-2026-49257 json | mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. In versions 3.0.1 and belo... | Not Provided | 2026-06-18 | 2026-06-22 |
| CVE-2026-48913 json | Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affe... | Not Provided | 2026-06-08 | 2026-06-08 |
| CVE-2026-44631 json | Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affect... | Not Provided | 2026-06-08 | 2026-06-08 |
| CVE-2026-44598 json | With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnera... | Not Provided | 2026-05-25 | 2026-05-26 |
| CVE-2026-44186 json | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with a... | Not Provided | 2026-06-08 | 2026-06-09 |
| CVE-2026-44185 json | Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This i... | Not Provided | 2026-06-08 | 2026-06-08 |
| CVE-2026-44119 json | Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read f... | Not Provided | 2026-06-08 | 2026-06-09 |
| CVE-2026-43951 json | Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This i... | Not Provided | 2026-06-08 | 2026-06-08 |
| CVE-2026-42536 json | Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This... | Not Provided | 2026-06-08 | 2026-06-08 |