
[CIVN-2026-0341] Multiple Vulnerabilities in Apache HTTP Server
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Apache HTTP Server
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Apache HTTP Server versions prior to 2.4.68
Overview
Multiple vulnerabilities have been reported in Apache HTTP Server which could be exploited by an attacker to bypass security restrictions, disclose sensitive information, escalate privileges, execute arbitrary code, perform cross-site scripting attacks, or cause denial of service (DoS) condition on the targeted system.
Target Audience:
System administrators, DevOps teams and organizations managing Apache HTTP Server.
Risk Assessment:
High risk of unauthorized access to sensitive data, bypass of security controls, possible remote code execution, privilege escalation, or disruption of services.
Impact Assessment:
Potential for arbitrary code execution, sensitive information disclosure, privilege escalation, system compromise, or service disruption.
Description
Apache HTTP Server is an open-source web server platform widely used for hosting web applications and websites, known for its reliability, performance, and cross-platform support.
Multiple vulnerabilities exist in Apache HTTP Server due to improper memory handling, insufficient access control, improper path validation, improper input validation, cross-site scripting issues, resource management flaws, and improper handling of backend responses in various components including mod_ldap, mod_proxy_ftp, mod_proxy_html, mod_dav_fs, mod_xml2enc, mod_headers, mod_mime, mod_ssl, and mod_http2.
Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, perform cross-site scripting attacks, bypass security restrictions, escalate privileges, execute arbitrary code, corrupt memory, or cause denial of service (DoS) condition on the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor:
https://httpd.apache.org/security/vulnerabilities_24.html#2.4.68
Vendor Information
Apache HTTP Server
https://httpd.apache.org/security/vulnerabilities_24.html#2.4.68
References
Apache HTTP Server
https://httpd.apache.org/security/vulnerabilities_24.html#2.4.68
CVE Name
CVE-2026-29167
CVE-2026-29170
CVE-2026-34355
CVE-2026-34356
CVE-2026-42535
CVE-2026-42536
CVE-2026-43951
CVE-2026-44119
CVE-2026-44185
CVE-2026-44186
CVE-2026-44631
CVE-2026-48913
CVE-2026-49975
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmo9OxIACgkQ3jCgcSdc
ys8VNxAAkGVV7LQaubD164YfFAalrb+5zNbdte+6Zl+sx3x+zXmXm1HfMXi6PxiF
CewH8DEcJoJWIcnY7VvWQRqoz8HmaeMrBxGUpv7cLF0LZnPLQmfsad/kxKIdGxsU
MTynSHEuJjQWfEmJdMBwPceW9U69PTgzSvPLToqEux11XCMOr8ZIMzBRpy7L0TsW
WnGk0Kg0b6oS778B7uwNPxuYNoNz6XzMyDW0wFwUVxtYX3up0iNc0Egm2mREzbKM
42oPXYXsV9fgg1763upQwpKWwk2YJSjKS5PkvzFgj8mZcqwtgCS1/vboDR9I5GTs
Aoto1UnS0cAnwoTkxlxZDdjwMXBj3eLk/PmT4lU0i1B9H3IhRxPcBFVw0dfxWIsz
9PMmWPmpkp4PFE5K3dlOMg7twS5vM4rSjq68ballXOATwuuoYQaOCm8Ne3oxj7sD
0iA0mR/AefLFH+qWzgplyjrCwCYPUS8lSjaalFYq5JkYS2GXZy6M3oIN2hblIXGQ
c4kvgGd5grjCKImDnZ9frU2QNb97W0q+4cOryfXFLawHtkKOoetHLvNkki/3EGkf
BIDMZikAQ3V15Zlt3dhx4td4NMqrZiCb4BgkoRKZlEY2Ef/QcWWgBSeds64bescB
nt/IeNNd1htfWacFL8wbIwhc++CpMkYwYltPFU9e09EQ0yvoPNo=
=6kz0
—–END PGP SIGNATURE—–


