VulnSea

http_server vulnerabilities

CVEs whose affected-version data names the http_server package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

13 CVEsRSS

CVE-2026-60530High· 7.8
2mo ago

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_http2.so)

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_http2.so). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to …

Twilightoracle · http_serverEPSS 0.16%via NVD
CVE-2026-60454High· 7.8
2mo ago

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with log…

Twilightoracle · http_serverEPSS 0.16%via NVD
CVE-2026-60438Critical· 9.1
2mo ago

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_ssl)

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_ssl). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with…

Midnightoracle · http_serverEPSS 0.43%via NVD
CVE-2026-60363Critical· 9.8
2mo ago

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Apache Plugin)

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Apache Plugin). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacke…

Midnightoracle · http_serverEPSS 0.51%via NVD
CVE-2026-44185High· 7.3
3mo ago

Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68,…

Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68,…

Twilightapache · http_serverEPSS 0.74%via NVD
CVE-2026-42536High· 7.5PoC
3mo ago

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68…

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68…

Midnightapache · http_serverEPSS 1.0%via NVD
CVE-2026-34355High· 7.5
3mo ago

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

Twilightapache · http_serverEPSS 1.2%via NVD
CVE-2026-28780Critical· 9.8
4mo ago

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker …

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker …

Midnightapache · http_serverEPSS 1.4%via NVD
CVE-2026-21962Critical· 10.0CISA KEVPoC
8mo ago

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS)

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versio…

Hadaloracle · http_serverEPSS 42%via NVD
CVE-2025-3891High· 7.5
1y ago

A flaw was found in the mod_auth_openidc module for Apache httpd

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The ser…

Twilightapache · http_serverEPSS 1.4%via NVD
CVE-2021-4034High· 7.8CISA KEVPoC
4y ago

A local privilege escalation vulnerability was found on polkit's pkexec utility

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current …

Abyssalpolkit_project · polkitEPSS 95%via NVD
CVE-2021-41617High· 7.0PoC
4y ago

sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected

sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and Authoriz…

Midnightopenbsd · opensshEPSS 2.5%via NVD
CVE-2021-40438Critical· 9.0CISA KEVPoC
5y ago

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

Hadalredhat · jboss_core_servicesEPSS 100%via NVD
http_server vulnerabilities (CVEs) · VulnSea