Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache HTTP Server — Vulnerabilities & Security Advisories 133

All 133 CVE vulnerabilities found in Apache HTTP Server, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the Apache HTTP Server. It collects known defects, including memory errors, authentication flaws, and configuration issues, covering advisories published over the last five years. Readers can track the vendor's security posture, understand specific weakness classes, and review the product's historical vulnerability timeline to assess risk.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2025-53020 Apache HTTP Server: HTTP/2 DoS by Memory Increase CWE-401 9.1 - 2025-07-10
CVE-2025-49812 Apache HTTP Server: mod_ssl TLS upgrade attack CWE-287 7.4AI High AI 2025-07-10
CVE-2025-49630 Apache HTTP Server: mod_proxy_http2 denial of service CWE-617 7.5AI High AI 2025-07-10
CVE-2025-23048 Apache HTTP Server: mod_ssl access control bypass with session resumption CWE-284 8.1AI High AI 2025-07-10
CVE-2024-43394 Apache HTTP Server: SSRF on Windows due to UNC paths CWE-918 7.5 - 2025-07-10
CVE-2024-47252 Apache HTTP Server: mod_ssl error log variable escaping CWE-150 5.3AI Medium AI 2025-07-10
CVE-2024-43204 Apache HTTP Server: SSRF with mod_headers setting Content-Type header CWE-918 5.9AI Medium AI 2025-07-10
CVE-2024-42516 Apache HTTP Server: HTTP response splitting CWE-20 5.3AI Medium AI 2025-07-10
CVE-2024-40725 Apache HTTP Server: source code disclosure with handlers configured via AddType CWE-668 7.5 - 2024-07-18
CVE-2024-40898 Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows CWE-918 7.5AI High AI 2024-07-18
CVE-2024-39884 Apache HTTP Server: source code disclosure with handlers configured via AddType 7.5 - 2024-07-04
CVE-2024-39573 Apache HTTP Server: mod_rewrite proxy handler substitution CWE-20 9.3AI Critical AI 2024-07-01
CVE-2024-38477 Apache HTTP Server: Crash resulting in Denial of Service in mod_proxy via a malicious request CWE-476 7.5 - 2024-07-01
CVE-2024-38476 Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect CWE-829 9.1AI Critical AI 2024-07-01
CVE-2024-38475 Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path. CWE-116 9.8AI Critical AI 2024-07-01
CVE-2024-38474 Apache HTTP Server weakness with encoded question marks in backreferences CWE-116 9.8AI Critical AI 2024-07-01
CVE-2024-38473 Apache HTTP Server proxy encoding problem CWE-116 9.8AI Critical AI 2024-07-01
CVE-2024-38472 Apache HTTP Server on WIndows UNC SSRF CWE-918 7.5AI High AI 2024-07-01
CVE-2024-36387 Apache HTTP Server: DoS by Null pointer in websocket over HTTP/2 CWE-476 7.5AI High AI 2024-07-01
CVE-2024-27316 Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames CWE-770 7.5 - 2024-04-04
CVE-2024-24795 Apache HTTP Server: HTTP Response Splitting in multiple modules CWE-113 9.1 - 2024-04-04
CVE-2023-38709 Apache HTTP Server: HTTP response splitting 7.5 - 2024-04-04
CVE-2023-31122 Apache HTTP Server: mod_macro buffer over-read CWE-125 7.5 - 2023-10-23
CVE-2023-43622 Apache HTTP Server: DoS in HTTP/2 with initial windows size 0 CWE-400 7.5 - 2023-10-23
CVE-2023-45802 Apache HTTP Server: HTTP/2 stream memory not reclaimed right away on RST CWE-404 5.9 - 2023-10-23
CVE-2023-27522 Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting CWE-444 5.3 - 2023-03-07
CVE-2023-25690 Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy CWE-444 6.5 - 2023-03-07
CVE-2022-37436 Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting CWE-113 7.5 - 2023-01-17
CVE-2022-36760 Apache HTTP Server: mod_proxy_ajp Possible request smuggling CWE-444 3.7 - 2023-01-17
CVE-2006-20001 Apache HTTP Server: mod_dav out of bounds read, or write of zero byte CWE-787 7.5 - 2023-01-17

All 133 known CVE vulnerabilities affecting Apache HTTP Server with full Chinese analysis, references, and POCs where available.