---
id: CVE-2026-42356
title: >-
  Deployment of wrong handler vulnerability in Apache HTTP Server allows the
  target of some internal redirects from CGI programs to also be treated as CGI
  and executed
summary: >-
  Deployment of wrong handler vulnerability in Apache HTTP Server allows the
  target of some internal redirects from CGI programs to also be treated as CGI
  and executed. The target must already be in a directory enabled for CGI and
  have no …
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-430
vendor: Apache Software Foundation
product: Apache HTTP Server
affected:
  - apache_http_server >= 2.4.60 <= 2.4.68
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T20:30:25.943'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42356'
references:
  - url: 'https://httpd.apache.org/security/vulnerabilities_24.html'
    label: security@apache.org
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-01T16:19:34.120406Z'
ingestedAt: '2026-10-01T18:55:42.356Z'
---

## Overview

Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime.



This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
