Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache HTTP Server — Vulnerabilities & Security Advisories 133

All 133 CVE vulnerabilities found in Apache HTTP Server, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the Apache HTTP Server. It collects known defects, including memory errors, authentication flaws, and configuration issues, covering advisories published over the last five years. Readers can track the vendor's security posture, understand specific weakness classes, and review the product's historical vulnerability timeline to assess risk.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2022-31813 mod_proxy X-Forwarded-For dropped by hop-by-hop mechanism CWE-348 9.8 - 2022-06-08
CVE-2022-30556 Information Disclosure in mod_lua with websockets CWE-200 - - 2022-06-08
CVE-2022-30522 mod_sed denial of service CWE-789 7.5 - 2022-06-08
CVE-2022-29404 Denial of service in mod_lua r:parsebody CWE-770 7.5 - 2022-06-08
CVE-2022-28615 Read beyond bounds in ap_strcmp_match() CWE-190 9.1 - 2022-06-08
CVE-2022-28614 read beyond bounds via ap_rwrite() CWE-190 5.3 - 2022-06-08
CVE-2022-28330 read beyond bounds in mod_isapi CWE-125 5.3 - 2022-06-08
CVE-2022-26377 mod_proxy_ajp: Possible request smuggling CWE-444 3.7 - 2022-06-08
CVE-2022-23943 mod_sed: Read/write beyond bounds CWE-787 9.1 - 2022-03-14
CVE-2022-22721 core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody CWE-190 9.1 - 2022-03-14
CVE-2022-22720 HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier CWE-444 9.8 - 2022-03-14
CVE-2022-22719 mod_lua Use of uninitialized value of in r:parsebody CWE-665 7.5 - 2022-03-14
CVE-2021-44224 Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlier CWE-476 8.2 - 2021-12-20
CVE-2021-44790 Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier CWE-787 9.8 - 2021-12-20
CVE-2021-42013 Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773) CWE-22 9.8 - 2021-10-07
CVE-2021-41773 Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 CWE-22 9.1 - 2021-10-05
CVE-2021-41524 null pointer dereference in h2 fuzzing CWE-476 7.5 - 2021-10-05
CVE-2021-40438 mod_proxy SSRF CWE-918 8.1 - 2021-09-16
CVE-2021-39275 ap_escape_quotes buffer overflow 9.8 - 2021-09-16
CVE-2021-36160 mod_proxy_uwsgi out of bound read CWE-125 7.5 - 2021-09-16
CVE-2021-34798 NULL pointer dereference in httpd core CWE-476 7.5 - 2021-09-16
CVE-2021-33193 Request splitting via HTTP/2 method injection and mod_proxy 7.5 - 2021-08-16
CVE-2021-31618 NULL pointer dereference on specially crafted HTTP/2 request CWE-476 7.5 - 2021-06-15
CVE-2021-30641 Unexpected URL matching with 'MergeSlashes OFF' 5.3 - 2021-06-10
CVE-2021-26691 Apache HTTP Server mod_session response handling heap overflow CWE-122 9.8 - 2021-06-10
CVE-2021-26690 mod_session NULL pointer dereference 7.5 - 2021-06-10
CVE-2020-13950 mod_proxy_http NULL pointer dereference 7.5 - 2021-06-10
CVE-2020-35452 mod_auth_digest possible stack overflow by one nul byte 9.4 - 2021-06-10
CVE-2020-13938 Improper Handling of Insufficient Privileges 5.5 - 2021-06-10
CVE-2019-17567 mod_proxy_wstunnel tunneling of non Upgraded connections - - 2021-06-10

All 133 known CVE vulnerabilities affecting Apache HTTP Server with full Chinese analysis, references, and POCs where available.