Apache HTTP Server administrators are urged to apply security updates following the disclosure of multiple vulnerabilities affecting Apache HTTP Server 2.4.
These vulnerabilities include flaws that could allow for remote code execution (RCE), server crashes, memory exhaustion, and other denial-of-service (DoS) conditions.
They impact various components of this widely used web server, particularly configurations that utilize HTTP/2, mod_rewrite, mod_proxy, WebDAV, and certain optional modules. Apache has released fixes across successive 2.4 versions, with the latest advisory documenting remediations up to version 2.4.68.
Among the most severe vulnerabilities is CVE-2024-38475, an important-severity flaw in mod_rewrite affecting Apache HTTP Server versions 2.4.59 and earlier.
This vulnerability stems from improper output escaping during rewrite processing. An attacker could exploit unsafe substitutions, specifically when a backreference or variable is used as the first segment of a substitution, to map a URL to filesystem locations that are permissible but were not intentionally exposed.
Apache has warned that this could lead to code execution or source code disclosure, depending on the server configuration and target environment. This flaw was addressed in Apache HTTP Server version 2.4.60.
Another important vulnerability, CVE-2024-38474, affects mod_rewrite’s handling of encoded question marks in backreferences.
A successful attack could permit adversaries to execute scripts in configured directories that are not directly accessible via a URL or disclose the source code of scripts intended for CGI execution only.
Apache resolved this issue in version 2.4.60 but noted that some previously functional rewrite rules may need to be reviewed. Administrators can use the UnsafeAllow3F flag only after confirming that affected substitutions are securely constrained.
CVE-2024-38476 is another important rating vulnerability that impacts the Apache HTTP Server core through version 2.4.59. This weakness could allow malicious or exploitable backend application response headers to invoke local handlers through an internal redirect.
The consequences could include information disclosure, server-side request forgery (SSRF), or local script execution, depending on server configuration and backend behavior. Apache’s fix may require organizations that rely on legacy AddType mappings for handler assignment to transition to affected configurations using SetHandler.
Denial-of-service risks are considerable, especially for HTTP/2 deployments. CVE-2026-49975, fixed in Apache HTTP Server version 2.4.68, is a moderate-severity vulnerability in mod_http2 that could cause DoS through malicious HTTP requests that trigger excessive memory allocation.
This affects versions 2.4.17 through 2.4.67. Separately, CVE-2026-44186 could cause an infinite loop in mod_proxy_ftp when communicating with an attacker-controlled backend FTP server.
At the same time, CVE-2026-42535 allows a WebDAV content author to manipulate trusted DAV property databases, potentially crashing child processes.
Organizations should prioritize upgrading to Apache HTTP Server 2.4.68, which contains fixes for the most recent issues.
Security teams should also audit RewriteRule, ProxyPassMatch, AddType, WebDAV, HTTP/2, and reverse-proxy configurations; disable unused modules; limit exposure to untrusted backends; and monitor logs for unusual request patterns, repeated HTTP/2 resets, unexpected internal redirects, and child-process crashes.
Timely patching and configuration hardening are crucial, as many of these flaws become exploitable only in specific, but common, module and deployment combinations.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…