Technology · Apache
Apache HTTP Server vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 32 vulnerabilities in Apache HTTP Server: 1 in the last 7 days and 1 in the last 90 days, 8 of them critical and 6 exploited in the wild. The most recent, CVE-2026-89281, was published on 22 September 2026.
- Last 7 days
- 1
- Last 90 days
- 1
- Critical, all time
- 8
- Exploited in the wild
- 6
About Apache HTTP Server
A robust, commercial-grade, featureful, and freely-available source code implementation of an HTTP (Web) server.
Latest Apache HTTP Server vulnerabilities
- CVE-2026-89281: Apache HTTP Server hardcoded openssl.cnf path vulnerability on WindowshighCVSS 8.4EPSS 0.1%
- CVE-2026-49975: Apache HTTP Server denial of service in mod_httpinfoCVSS 0
- CVE-2026-48913: Apache HTTP Server use after free in mod_http2info
- CVE-2026-44631: Apache HTTP Server buffer underwrite in ap_regname via configurationinfo
- CVE-2026-44186: Apache HTTP Server infinite loop in mod_proxy_ftpinfo
- CVE-2026-44185: Apache HTTP Server buffer over-read in mod_ssl OCSP send_requestinfoCVSS 0
- CVE-2026-44119: Apache HTTP Server privilege escalation via expressions in .htaccessinfoCVSS 0
- CVE-2026-43951: Apache HTTP Server OOB read in merge_response_headersinfoCVSS 5.3
- CVE-2026-42536: Apache HTTP Server heap overflow in mod_xml2encinfo
- CVE-2026-42535: Apache HTTP Server mod_dav_fs path handling issueinfoCVSS 5.3
- CVE-2026-34356: Apache HTTP Server heap overflow in ProxyPassReverseCookie directivesinfoCVSS 0
- CVE-2026-34355: Apache HTTP Server buffer overflow in mod_proxy_htmlinfo
- CVE-2026-29170: Apache HTTP Server XSS in mod_proxy_ftp directory listinginfoCVSS 0
- CVE-2026-29167: Apache HTTP Server use after free in mod_ldapinfo
- CVE-2026-28780: Apache HTTP Server heap overflow in mod_proxy_ajpcriticalCVSS 9.8EPSS 0.7%
- CVE-2026-23918: Apache HTTP Server double free in HTTP/2 protocolhighCVSS 8.8EPSS 42.8%
- CVE-2025-58098: Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the…highCVSS 8.3EPSS 1.4%
- CVE-2025-65082: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment…mediumCVSS 6.5EPSS 0.8%
- CVE-2025-59775: Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server on Windows with AllowEncodedSlashes On and…highCVSS 7.5EPSS 0.8%
- CVE-2024-38475: Apache HTTP Server Improper Escaping of Output Vulnerabilitycriticalexploited in the wildCVSS 9.1
- CVE-2023-44487: HTTP/2 Rapid Reset Attack Vulnerabilitycriticalexploited in the wildCVSS 7.5
- CVE-2021-40438: Apache HTTP Server-Side Request Forgery (SSRF)criticalexploited in the wildCVSS 9
- CVE-2021-42013: Apache HTTP Server Path Traversal Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2019-0211: Apache HTTP Server Privilege Escalation Vulnerabilitycriticalexploited in the wildCVSS 7.8
- CVE-2021-41773: Apache HTTP Server Path Traversal Vulnerabilitycriticalexploited in the wildCVSS 9.8
Most severe Apache HTTP Server vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2021-41773: Apache HTTP Server Path Traversal Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2021-42013: Apache HTTP Server Path Traversal Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2024-38475: Apache HTTP Server Improper Escaping of Output Vulnerabilitycriticalexploited in the wildCVSS 9.1
- CVE-2021-40438: Apache HTTP Server-Side Request Forgery (SSRF)criticalexploited in the wildCVSS 9
- CVE-2019-0211: Apache HTTP Server Privilege Escalation Vulnerabilitycriticalexploited in the wildCVSS 7.8
- CVE-2023-44487: HTTP/2 Rapid Reset Attack Vulnerabilitycriticalexploited in the wildCVSS 7.5
- CVE-1999-0067: NCSA/Apache phf CGI program OS command injectioncriticalCVSS 10
- CVE-2026-28780: Apache HTTP Server heap overflow in mod_proxy_ajpcriticalCVSS 9.8EPSS 0.7%
- CVE-2026-23918: Apache HTTP Server double free in HTTP/2 protocolhighCVSS 8.8EPSS 42.8%
- CVE-2026-89281: Apache HTTP Server hardcoded openssl.cnf path vulnerability on WindowshighCVSS 8.4EPSS 0.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 1 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/http-server.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Apache HTTP Server vulnerabilities", https://junglewise.ai/threats/technologies/http-server, 26 September 2026.