Vulnerabilidades de Apache HTTP Server

Vulnerabilidades recientes que afectan a Apache HTTP Server en servidores Linux, con su severidad y la versión que las corrige. Ahora mismo seguimos 20 avisos, 19 con versión corregida publicada.

CVE-2026-42356 Baja 3.7 2026-10-01

Apache HTTP Server

Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a…

Corregida en Debian 14.

CVE-2026-42528 Media 4.3 2026-10-01

Apache HTTP Server

A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes. Users are recommended to upgrade to…

Corregida en Debian 14.

CVE-2026-46729 Alta 7.5 2026-10-01

Apache HTTP Server

NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Corregida en Debian 14.

CVE-2026-47360 Alta 7.5 2026-10-01

Apache HTTP Server

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.   When SessionCookieRemove changes across internal redirects, the…

Corregida en Debian 14.

CVE-2026-48005 Alta 7.5 2026-10-01

Apache HTTP Server

Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service…

Corregida en Debian 14.

CVE-2026-56153 Alta 7.5 2026-10-01

Apache HTTP Server

Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Corregida en Debian 14.

CVE-2026-56154 Crítica 9.8 2026-10-01

Apache HTTP Server

Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Corregida en Debian 14.

CVE-2026-56449 Alta 7.5 2026-10-01

Apache HTTP Server

Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Corregida en Debian 14.

CVE-2026-57941 Crítica 9.8 2026-10-01

Apache HTTP Server

Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Corregida en Debian 14.

CVE-2026-58415 Media 5.3 2026-10-01

Apache HTTP Server

Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties…

Corregida en Debian 14.

CVE-2026-59685 Alta 7.5 2026-10-01

Apache HTTP Server

Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Sin parche todavía.

CVE-2026-59797 Crítica 9.8 2026-10-01

Apache HTTP Server

Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Corregida en Debian 14.

CVE-2026-63045 Alta 7.5 2026-10-01

Apache HTTP Server

Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted…

Corregida en Debian 14.

CVE-2026-63292 Alta 7.5 2026-10-01

Apache HTTP Server

Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially…

Corregida en Debian 14.

CVE-2026-63686 Alta 7.5 2026-10-01

Apache HTTP Server

A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied…

Corregida en Debian 14.

CVE-2026-63718 Alta 7.5 2026-10-01

Apache HTTP Server

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with…

Corregida en Debian 14.

CVE-2026-73636 Alta 8.1 2026-10-01

Apache HTTP Server

Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest…

Corregida en Debian 14.

CVE-2026-73637 Alta 7.3 2026-10-01

Apache HTTP Server

Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via…

Corregida en Debian 14.

CVE-2026-79768 Media 5.3 2026-10-01

Apache HTTP Server

Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form…

Corregida en Debian 14.

CVE-2026-93546 Alta 8.8 2026-10-01

Apache HTTP Server

Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property…

Corregida en Debian 14.

Datos de OSV.dev, publicados bajo licencia CC BY 4.0. Se recopilan a diario y se filtran al software que seguimos; así se elabora la lista.