{"schema_version":1,"title":"Apache HTTP Server vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 32 vulnerabilities in Apache HTTP Server: 1 in the last 7 days and 1 in the last 90 days, 8 of them critical and 6 exploited in the wild. The most recent, CVE-2026-89281, was published on 22 September 2026.","url":"https://junglewise.ai/threats/technologies/http-server","json_url":"https://junglewise.ai/threats/technologies/http-server.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/http-server","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":7,"all_time":32,"critical":8,"exploited":6,"last_7_days":1,"last_30_days":1,"last_90_days":1,"last_365_days":19},"latest":[{"cve":"CVE-2026-89281","cvss":8.4,"epss":0.0013,"slug":"cve-2026-89281-the-apache-lounge-windows-distribution-of-apache-http-server","title":"Apache HTTP Server hardcoded openssl.cnf path vulnerability on Windows","severity":"high","exploited":false,"published_at":"2026-09-22T20:17:11.38+00:00","url":"https://junglewise.ai/threats/cve-2026-89281-the-apache-lounge-windows-distribution-of-apache-http-server"},{"cve":"CVE-2026-49975","cvss":0,"slug":"cve-2026-49975-apache-http-server-denial-of-service-in-mod-http","title":"Apache HTTP Server denial of service in mod_http","severity":"info","exploited":false,"published_at":"2026-06-08T16:16:44.223+00:00","url":"https://junglewise.ai/threats/cve-2026-49975-apache-http-server-denial-of-service-in-mod-http"},{"cve":"CVE-2026-48913","slug":"cve-2026-48913-apache-http-server-use-after-free-in-mod-http2","title":"Apache HTTP Server use after free in mod_http2","severity":"info","exploited":false,"published_at":"2026-06-08T16:16:43.39+00:00","url":"https://junglewise.ai/threats/cve-2026-48913-apache-http-server-use-after-free-in-mod-http2"},{"cve":"CVE-2026-44631","slug":"cve-2026-44631-apache-http-server-buffer-underwrite-in-ap-regname-via","title":"Apache HTTP Server buffer underwrite in ap_regname via configuration","severity":"info","exploited":false,"published_at":"2026-06-08T16:16:40.583+00:00","url":"https://junglewise.ai/threats/cve-2026-44631-apache-http-server-buffer-underwrite-in-ap-regname-via"},{"cve":"CVE-2026-44186","slug":"cve-2026-44186-apache-http-server-infinite-loop-in-mod-proxy-ftp","title":"Apache HTTP Server infinite loop in mod_proxy_ftp","severity":"info","exploited":false,"published_at":"2026-06-08T16:16:40.453+00:00","url":"https://junglewise.ai/threats/cve-2026-44186-apache-http-server-infinite-loop-in-mod-proxy-ftp"},{"cve":"CVE-2026-44185","cvss":0,"slug":"cve-2026-44185-apache-http-server-buffer-over-read-in-mod-ssl-ocsp-send-request","title":"Apache HTTP Server buffer over-read in mod_ssl OCSP send_request","severity":"info","exploited":false,"published_at":"2026-06-08T16:16:40.327+00:00","url":"https://junglewise.ai/threats/cve-2026-44185-apache-http-server-buffer-over-read-in-mod-ssl-ocsp-send-request"},{"cve":"CVE-2026-44119","cvss":0,"slug":"cve-2026-44119-apache-http-server-privilege-escalation-via-expressions-in","title":"Apache HTTP Server privilege escalation via expressions in .htaccess","severity":"info","exploited":false,"published_at":"2026-06-08T16:16:40.203+00:00","url":"https://junglewise.ai/threats/cve-2026-44119-apache-http-server-privilege-escalation-via-expressions-in"},{"cve":"CVE-2026-43951","cvss":5.3,"slug":"cve-2026-43951-apache-http-server-oob-read-in-merge-response-headers","title":"Apache HTTP Server OOB read in merge_response_headers","severity":"info","exploited":false,"published_at":"2026-06-08T16:16:40.087+00:00","url":"https://junglewise.ai/threats/cve-2026-43951-apache-http-server-oob-read-in-merge-response-headers"},{"cve":"CVE-2026-42536","slug":"cve-2026-42536-apache-http-server-heap-overflow-in-mod-xml2enc","title":"Apache HTTP Server heap overflow in mod_xml2enc","severity":"info","exploited":false,"published_at":"2026-06-08T16:16:39.263+00:00","url":"https://junglewise.ai/threats/cve-2026-42536-apache-http-server-heap-overflow-in-mod-xml2enc"},{"cve":"CVE-2026-42535","cvss":5.3,"slug":"cve-2026-42535-apache-http-server-mod-dav-fs-path-handling-issue","title":"Apache HTTP Server mod_dav_fs path handling issue","severity":"info","exploited":false,"published_at":"2026-06-08T16:16:39.127+00:00","url":"https://junglewise.ai/threats/cve-2026-42535-apache-http-server-mod-dav-fs-path-handling-issue"},{"cve":"CVE-2026-34356","cvss":0,"slug":"cve-2026-34356-apache-http-server-heap-overflow-in-proxypassreversecookie","title":"Apache HTTP Server heap overflow in ProxyPassReverseCookie directives","severity":"info","exploited":false,"published_at":"2026-06-08T16:16:38.537+00:00","url":"https://junglewise.ai/threats/cve-2026-34356-apache-http-server-heap-overflow-in-proxypassreversecookie"},{"cve":"CVE-2026-34355","slug":"cve-2026-34355-apache-http-server-buffer-overflow-in-mod-proxy-html","title":"Apache HTTP Server buffer overflow in mod_proxy_html","severity":"info","exploited":false,"published_at":"2026-06-08T16:16:38.387+00:00","url":"https://junglewise.ai/threats/cve-2026-34355-apache-http-server-buffer-overflow-in-mod-proxy-html"},{"cve":"CVE-2026-29170","cvss":0,"slug":"cve-2026-29170-apache-http-server-xss-in-mod-proxy-ftp-directory-listing","title":"Apache HTTP Server XSS in mod_proxy_ftp directory listing","severity":"info","exploited":false,"published_at":"2026-06-08T16:16:38.093+00:00","url":"https://junglewise.ai/threats/cve-2026-29170-apache-http-server-xss-in-mod-proxy-ftp-directory-listing"},{"cve":"CVE-2026-29167","slug":"cve-2026-29167-apache-http-server-use-after-free-in-mod-ldap","title":"Apache HTTP Server use after free in mod_ldap","severity":"info","exploited":false,"published_at":"2026-06-08T16:16:37.967+00:00","url":"https://junglewise.ai/threats/cve-2026-29167-apache-http-server-use-after-free-in-mod-ldap"},{"cve":"CVE-2026-28780","cvss":9.8,"epss":0.0072,"slug":"cve-2026-28780-apache-http-server-heap-overflow-in-mod-proxy-ajp","title":"Apache HTTP Server heap overflow in mod_proxy_ajp","severity":"critical","exploited":false,"published_at":"2026-05-05T22:16:00.39+00:00","url":"https://junglewise.ai/threats/cve-2026-28780-apache-http-server-heap-overflow-in-mod-proxy-ajp"},{"cve":"CVE-2026-23918","cvss":8.8,"epss":0.428,"slug":"cve-2026-23918-apache-http-server-double-free-in-http-2-protocol","title":"Apache HTTP Server double free in HTTP/2 protocol","severity":"high","exploited":false,"published_at":"2026-05-04T15:16:03.583+00:00","url":"https://junglewise.ai/threats/cve-2026-23918-apache-http-server-double-free-in-http-2-protocol"},{"cve":"CVE-2025-58098","cvss":8.3,"epss":0.0142,"slug":"cve-2025-58098-apache-http-server-2-4-65-and-earlier-with-server-side-includes","title":"Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query","severity":"high","exploited":false,"published_at":"2025-12-05T14:15:49.153+00:00","url":"https://junglewise.ai/threats/cve-2025-58098-apache-http-server-2-4-65-and-earlier-with-server-side-includes"},{"cve":"CVE-2025-65082","cvss":6.5,"epss":0.0081,"slug":"cve-2025-65082-improper-neutralization-of-escape-meta-or-control-sequences","title":"Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the","severity":"medium","exploited":false,"published_at":"2025-12-05T11:15:52.497+00:00","url":"https://junglewise.ai/threats/cve-2025-65082-improper-neutralization-of-escape-meta-or-control-sequences"},{"cve":"CVE-2025-59775","cvss":7.5,"epss":0.0082,"slug":"cve-2025-59775-server-side-request-forgery-ssrf-vulnerability-in-apache-http","title":"Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off all","severity":"high","exploited":false,"published_at":"2025-12-05T11:15:52.21+00:00","url":"https://junglewise.ai/threats/cve-2025-59775-server-side-request-forgery-ssrf-vulnerability-in-apache-http"},{"cve":"CVE-2024-38475","cvss":9.1,"slug":"cve-2024-38475-apache-http-server-improper-escaping-of-output-vulnerability","title":"Apache HTTP Server Improper Escaping of Output Vulnerability","severity":"critical","exploited":true,"published_at":"2025-05-01T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-38475-apache-http-server-improper-escaping-of-output-vulnerability"},{"cve":"CVE-2023-44487","cvss":5.3,"epss":1,"slug":"cve-2023-44487-http-2-rapid-reset-attack-vulnerability","title":"Multiple Vendors HTTP/2 denial of service via Rapid Reset attack","severity":"critical","exploited":true,"published_at":"2023-10-10T21:28:24+00:00","url":"https://junglewise.ai/threats/cve-2023-44487-http-2-rapid-reset-attack-vulnerability"},{"cve":"CVE-2021-40438","cvss":9,"slug":"cve-2021-40438-apache-http-server-side-request-forgery-ssrf","title":"Apache HTTP Server-Side Request Forgery (SSRF)","severity":"critical","exploited":true,"published_at":"2021-12-01T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-40438-apache-http-server-side-request-forgery-ssrf"},{"cve":"CVE-2021-42013","cvss":9.8,"slug":"cve-2021-42013-apache-http-server-path-traversal-vulnerability","title":"Apache HTTP Server Path Traversal Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-42013-apache-http-server-path-traversal-vulnerability"},{"cve":"CVE-2019-0211","cvss":7.8,"slug":"cve-2019-0211-apache-http-server-privilege-escalation-vulnerability","title":"Apache HTTP Server Privilege Escalation Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2019-0211-apache-http-server-privilege-escalation-vulnerability"},{"cve":"CVE-2021-41773","cvss":9.8,"slug":"cve-2021-41773-apache-http-server-path-traversal-vulnerability","title":"Apache HTTP Server Path Traversal Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-41773-apache-http-server-path-traversal-vulnerability"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Apache Tomcat","slug":"tomcat","vulnerabilities":78,"url":"https://junglewise.ai/threats/technologies/tomcat"},{"name":"Apache Airflow","slug":"airflow","vulnerabilities":63,"url":"https://junglewise.ai/threats/technologies/airflow"},{"name":"Apache Camel","slug":"camel","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/camel"},{"name":"Apache Traffic Server","slug":"traffic-server","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/traffic-server"},{"name":"Apache CloudStack","slug":"cloudstack","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/cloudstack"},{"name":"Apache Ofbiz","slug":"ofbiz","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/ofbiz"},{"name":"Apache ActiveMQ","slug":"activemq","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/activemq"},{"name":"Apache Storm","slug":"storm","vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/storm"},{"name":"Apache Apisix","slug":"apisix","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/apisix"},{"name":"Apache Thrift","slug":"thrift","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/thrift"},{"name":"Apache ActiveMQ Artemis","slug":"activemq-artemis","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/activemq-artemis"},{"name":"Apache Ranger","slug":"ranger","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/ranger"}],"technology":{"hub":true,"name":"Apache HTTP Server","slug":"http-server","vendor":{"name":"Apache","slug":"apache","url":"https://junglewise.ai/threats/vendors/apache"},"aliases":[],"category":"web-server","homepage":"https://httpd.apache.org/","repo_url":"https://github.com/apache/httpd","description":"A robust, commercial-grade, featureful, and freely-available source code implementation of an HTTP (Web) server.","url":"https://junglewise.ai/threats/technologies/http-server"},"most_severe":[{"cve":"CVE-2021-41773","cvss":9.8,"slug":"cve-2021-41773-apache-http-server-path-traversal-vulnerability","title":"Apache HTTP Server Path Traversal Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-41773-apache-http-server-path-traversal-vulnerability"},{"cve":"CVE-2021-42013","cvss":9.8,"slug":"cve-2021-42013-apache-http-server-path-traversal-vulnerability","title":"Apache HTTP Server Path Traversal Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-42013-apache-http-server-path-traversal-vulnerability"},{"cve":"CVE-2024-38475","cvss":9.1,"slug":"cve-2024-38475-apache-http-server-improper-escaping-of-output-vulnerability","title":"Apache HTTP Server Improper Escaping of Output Vulnerability","severity":"critical","exploited":true,"published_at":"2025-05-01T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-38475-apache-http-server-improper-escaping-of-output-vulnerability"},{"cve":"CVE-2021-40438","cvss":9,"slug":"cve-2021-40438-apache-http-server-side-request-forgery-ssrf","title":"Apache HTTP Server-Side Request Forgery (SSRF)","severity":"critical","exploited":true,"published_at":"2021-12-01T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-40438-apache-http-server-side-request-forgery-ssrf"},{"cve":"CVE-2019-0211","cvss":7.8,"slug":"cve-2019-0211-apache-http-server-privilege-escalation-vulnerability","title":"Apache HTTP Server Privilege Escalation Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2019-0211-apache-http-server-privilege-escalation-vulnerability"},{"cve":"CVE-2023-44487","cvss":5.3,"epss":1,"slug":"cve-2023-44487-http-2-rapid-reset-attack-vulnerability","title":"Multiple Vendors HTTP/2 denial of service via Rapid Reset attack","severity":"critical","exploited":true,"published_at":"2023-10-10T21:28:24+00:00","url":"https://junglewise.ai/threats/cve-2023-44487-http-2-rapid-reset-attack-vulnerability"},{"cve":"CVE-1999-0067","cvss":10,"slug":"cve-1999-0067-ncsa-apache-phf-cgi-program-os-command-injection","title":"NCSA/Apache phf CGI program OS command injection","severity":"critical","exploited":false,"published_at":"1996-03-20T05:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0067-ncsa-apache-phf-cgi-program-os-command-injection"},{"cve":"CVE-2026-28780","cvss":9.8,"epss":0.0072,"slug":"cve-2026-28780-apache-http-server-heap-overflow-in-mod-proxy-ajp","title":"Apache HTTP Server heap overflow in mod_proxy_ajp","severity":"critical","exploited":false,"published_at":"2026-05-05T22:16:00.39+00:00","url":"https://junglewise.ai/threats/cve-2026-28780-apache-http-server-heap-overflow-in-mod-proxy-ajp"},{"cve":"CVE-2026-23918","cvss":8.8,"epss":0.428,"slug":"cve-2026-23918-apache-http-server-double-free-in-http-2-protocol","title":"Apache HTTP Server double free in HTTP/2 protocol","severity":"high","exploited":false,"published_at":"2026-05-04T15:16:03.583+00:00","url":"https://junglewise.ai/threats/cve-2026-23918-apache-http-server-double-free-in-http-2-protocol"},{"cve":"CVE-2026-89281","cvss":8.4,"epss":0.0013,"slug":"cve-2026-89281-the-apache-lounge-windows-distribution-of-apache-http-server","title":"Apache HTTP Server hardcoded openssl.cnf path vulnerability on Windows","severity":"high","exploited":false,"published_at":"2026-09-22T20:17:11.38+00:00","url":"https://junglewise.ai/threats/cve-2026-89281-the-apache-lounge-windows-distribution-of-apache-http-server"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}