[CIVN-2026-0341] Multiple Vulnerabilities in Apache HTTP Server

By Published On: June 25, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Apache HTTP Server


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


Apache HTTP Server versions prior to 2.4.68

Overview


Multiple vulnerabilities have been reported in Apache HTTP Server which could be exploited by an attacker to bypass security restrictions, disclose sensitive information, escalate privileges, execute arbitrary code, perform cross-site scripting attacks, or cause denial of service (DoS) condition on the targeted system.


Target Audience:

System administrators, DevOps teams and organizations managing Apache HTTP Server.


Risk Assessment:

High risk of unauthorized access to sensitive data, bypass of security controls, possible remote code execution, privilege escalation, or disruption of services.


Impact Assessment:

Potential for arbitrary code execution, sensitive information disclosure, privilege escalation, system compromise, or service disruption.


Description


Apache HTTP Server is an open-source web server platform widely used for hosting web applications and websites, known for its reliability, performance, and cross-platform support.


Multiple vulnerabilities exist in Apache HTTP Server due to improper memory handling, insufficient access control, improper path validation, improper input validation, cross-site scripting issues, resource management flaws, and improper handling of backend responses in various components including mod_ldap, mod_proxy_ftp, mod_proxy_html, mod_dav_fs, mod_xml2enc, mod_headers, mod_mime, mod_ssl, and mod_http2.


Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, perform cross-site scripting attacks, bypass security restrictions, escalate privileges, execute arbitrary code, corrupt memory, or cause denial of service (DoS) condition on the targeted system.


Solution


Apply appropriate updates as mentioned by the vendor:

https://httpd.apache.org/security/vulnerabilities_24.html#2.4.68



Vendor Information


Apache HTTP Server

https://httpd.apache.org/security/vulnerabilities_24.html#2.4.68


References


Apache HTTP Server

https://httpd.apache.org/security/vulnerabilities_24.html#2.4.68


CVE Name

CVE-2026-29167

CVE-2026-29170

CVE-2026-34355

CVE-2026-34356

CVE-2026-42535

CVE-2026-42536

CVE-2026-43951

CVE-2026-44119

CVE-2026-44185

CVE-2026-44186

CVE-2026-44631

CVE-2026-48913

CVE-2026-49975




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmo9OxIACgkQ3jCgcSdc

ys8VNxAAkGVV7LQaubD164YfFAalrb+5zNbdte+6Zl+sx3x+zXmXm1HfMXi6PxiF

CewH8DEcJoJWIcnY7VvWQRqoz8HmaeMrBxGUpv7cLF0LZnPLQmfsad/kxKIdGxsU

MTynSHEuJjQWfEmJdMBwPceW9U69PTgzSvPLToqEux11XCMOr8ZIMzBRpy7L0TsW

WnGk0Kg0b6oS778B7uwNPxuYNoNz6XzMyDW0wFwUVxtYX3up0iNc0Egm2mREzbKM

42oPXYXsV9fgg1763upQwpKWwk2YJSjKS5PkvzFgj8mZcqwtgCS1/vboDR9I5GTs

Aoto1UnS0cAnwoTkxlxZDdjwMXBj3eLk/PmT4lU0i1B9H3IhRxPcBFVw0dfxWIsz

9PMmWPmpkp4PFE5K3dlOMg7twS5vM4rSjq68ballXOATwuuoYQaOCm8Ne3oxj7sD

0iA0mR/AefLFH+qWzgplyjrCwCYPUS8lSjaalFYq5JkYS2GXZy6M3oIN2hblIXGQ

c4kvgGd5grjCKImDnZ9frU2QNb97W0q+4cOryfXFLawHtkKOoetHLvNkki/3EGkf

BIDMZikAQ3V15Zlt3dhx4td4NMqrZiCb4BgkoRKZlEY2Ef/QcWWgBSeds64bescB

nt/IeNNd1htfWacFL8wbIwhc++CpMkYwYltPFU9e09EQ0yvoPNo=

=6kz0

—–END PGP SIGNATURE—–

Share this article