| httpd: httpd: Denial of Service via integer overflow in mod_dav_fs CVE-2026-93546 | Severity high |
| httpd: httpd: Information disclosure in mod_userdir via single-dot path equivalence CVE-2026-79768 | Severity medium |
| httpd: httpd: Authentication state corruption via concurrent Digest authentication requests CVE-2026-73637 | Severity high |
| httpd: httpd: Authentication bypass via credential replay in mod_auth_digest CVE-2026-73636 | Severity high |
| httpd: httpd: Denial of Service via charset conversion failure in mod_xml2enc CVE-2026-63686 | Severity high |
| httpd: httpd: Arbitrary code execution via oversized Host header in mod_vhost_alias CVE-2026-63292 | Severity high |
| httpd: httpd: unauthorized connection to arbitrary hosts via crafted FTP PASV response CVE-2026-63045 | Severity high |
| Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.
This issue… CVE-2026-59797 | Severity critical |
| httpd: httpd: Denial of Service via out-of-bounds write during Windows path expansion CVE-2026-59685 | Severity high |
| httpd: httpd: Information disclosure via direct request to the WebDAV state directory CVE-2026-58415 | Severity medium |
| Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy
This issue affects Apache HTTP… CVE-2026-57941 | Severity critical |
| httpd: httpd: Denial of Service via crafted HTTP response bodies in mod_proxy_html CVE-2026-56449 | Severity high |
| Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...})
This issue affects Apache HTTP… CVE-2026-56154 | Severity critical |
| httpd: httpd: Denial of Service via heap-based buffer overflow in mod_charset_lite CVE-2026-56153 | Severity high |
| httpd: httpd: Denial of service via forged Authorization headers in mod_auth_digest CVE-2026-48005 | Severity high |
| httpd: httpd: Information disclosure via session cookie leakage during internal redirects CVE-2026-47360 | Severity high |
| httpd: httpd: mod_heartmonitor: Denial of Service via NULL pointer dereference CVE-2026-46729 | Severity high |
| httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server CVE-2026-44185 | Severity high |
| httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc CVE-2026-42536 | Severity high |
| httpd: httpd: Denial of Service via mod_dav shared lock memory calculation error CVE-2026-42528 | Severity medium |
| httpd: httpd: arbitrary code execution via incorrect handler assignment during internal CGI redirects CVE-2026-42356 | Severity low |
| httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass CVE-2026-34355 | Severity high |
| Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow CVE-2026-28780 | Severity critical |
| httpd: Apache HTTP Server: CGI environment variable override CVE-2025-65082 | Severity medium |
| httpd: Apache HTTP Server: NTLM Leakage on Windows via SSRF CVE-2025-59775 | Severity high |
| httpd: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... CVE-2025-58098 | Severity high |
| mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include… CVE-2000-0913 | |