Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2345

Browse all 2345 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

Found 119 results / 2345 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2025-53020 Apache HTTP Server: HTTP/2 DoS by Memory Increase — Apache HTTP Server CWE-401 9.1 - 2025-07-10
CVE-2025-49812 Apache HTTP Server: mod_ssl TLS upgrade attack — Apache HTTP Server CWE-287 7.4AI High AI 2025-07-10
CVE-2025-49630 Apache HTTP Server: mod_proxy_http2 denial of service — Apache HTTP Server CWE-617 7.5AI High AI 2025-07-10
CVE-2025-23048 Apache HTTP Server: mod_ssl access control bypass with session resumption — Apache HTTP Server CWE-284 8.1AI High AI 2025-07-10
CVE-2024-43394 Apache HTTP Server: SSRF on Windows due to UNC paths — Apache HTTP Server CWE-918 7.5 - 2025-07-10
CVE-2024-47252 Apache HTTP Server: mod_ssl error log variable escaping — Apache HTTP Server CWE-150 5.3AI Medium AI 2025-07-10
CVE-2024-43204 Apache HTTP Server: SSRF with mod_headers setting Content-Type header — Apache HTTP Server CWE-918 5.9AI Medium AI 2025-07-10
CVE-2024-42516 Apache HTTP Server: HTTP response splitting — Apache HTTP Server CWE-20 5.3AI Medium AI 2025-07-10
CVE-2024-40725 Apache HTTP Server: source code disclosure with handlers configured via AddType — Apache HTTP Server CWE-668 7.5 - 2024-07-18
CVE-2024-40898 Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows — Apache HTTP Server CWE-918 7.5AI High AI 2024-07-18
CVE-2024-39884 Apache HTTP Server: source code disclosure with handlers configured via AddType — Apache HTTP Server 7.5 - 2024-07-04
CVE-2024-39573 Apache HTTP Server: mod_rewrite proxy handler substitution — Apache HTTP Server CWE-20 9.3AI Critical AI 2024-07-01
CVE-2024-38477 Apache HTTP Server: Crash resulting in Denial of Service in mod_proxy via a malicious request — Apache HTTP Server CWE-476 7.5 - 2024-07-01
CVE-2024-38476 Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect — Apache HTTP Server CWE-829 9.1AI Critical AI 2024-07-01
CVE-2024-38475 Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path. — Apache HTTP Server CWE-116 9.8AI Critical AI 2024-07-01
CVE-2024-38474 Apache HTTP Server weakness with encoded question marks in backreferences — Apache HTTP Server CWE-116 9.8AI Critical AI 2024-07-01
CVE-2024-38473 Apache HTTP Server proxy encoding problem — Apache HTTP Server CWE-116 9.8AI Critical AI 2024-07-01
CVE-2024-38472 Apache HTTP Server on WIndows UNC SSRF — Apache HTTP Server CWE-918 7.5AI High AI 2024-07-01
CVE-2024-36387 Apache HTTP Server: DoS by Null pointer in websocket over HTTP/2 — Apache HTTP Server CWE-476 7.5AI High AI 2024-07-01
CVE-2024-27316 Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames — Apache HTTP Server CWE-770 7.5 - 2024-04-04
CVE-2024-24795 Apache HTTP Server: HTTP Response Splitting in multiple modules — Apache HTTP Server CWE-113 9.1 - 2024-04-04
CVE-2023-38709 Apache HTTP Server: HTTP response splitting — Apache HTTP Server 7.5 - 2024-04-04
CVE-2023-31122 Apache HTTP Server: mod_macro buffer over-read — Apache HTTP Server CWE-125 7.5 - 2023-10-23
CVE-2023-43622 Apache HTTP Server: DoS in HTTP/2 with initial windows size 0 — Apache HTTP Server CWE-400 7.5 - 2023-10-23
CVE-2023-45802 Apache HTTP Server: HTTP/2 stream memory not reclaimed right away on RST — Apache HTTP Server CWE-404 5.9 - 2023-10-23
CVE-2023-27522 Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting — Apache HTTP Server CWE-444 5.3 - 2023-03-07
CVE-2023-25690 Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy — Apache HTTP Server CWE-444 6.5 - 2023-03-07
CVE-2022-37436 Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting — Apache HTTP Server CWE-113 7.5 - 2023-01-17
CVE-2022-36760 Apache HTTP Server: mod_proxy_ajp Possible request smuggling — Apache HTTP Server CWE-444 3.7 - 2023-01-17
CVE-2006-20001 Apache HTTP Server: mod_dav out of bounds read, or write of zero byte — Apache HTTP Server CWE-787 7.5 - 2023-01-17

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.