Exposure of Apache HTTP Server

Web servers
595
exposure score
1,580,941
sites use
5
exploited
20
critical
Vexday analysis

O Apache HTTP Server acumula 169 CVEs catalogadas, com 16 classificadas como críticas e 34 surgidas apenas nos últimos 90 dias, sinalizando um ritmo elevado de descobertas recentes que exige atenção contínua. A taxa de exploração ativa é 6,6 vezes acima da média geral do catálogo CISA KEV, com 5 vulnerabilidades confirmadas em uso por agentes de ameaça — proporção que coloca o servidor entre as tecnologias de maior risco operacional imediato. A CVE mais perigosa atualmente ativa, CVE-2021-40438, apresenta EPSS de 1,0, o valor máximo possível, indicando probabilidade praticamente certa de exploração observada no ambiente real. O tipo de falha mais recorrente é CWE-476 (desreferência de ponteiro nulo), embora o perfil de risco mais crítico esteja nas vulnerabilidades com exploração confirmada, que devem ser priorizadas em qualquer plano de remediação.

CVEs

178 results
CVE-2022-23943mod_sed: Read/write beyond boundsEPSS 50.4%CVE-2026-23918HIGHApache HTTP Server: http2: double free and possible RCE on early resetEPSS 49.7%CVE-2020-13950mod_proxy_http NULL pointer dereferenceEPSS 49.1%CVE-2016-0736In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possiblyEPSS 49.0%CVE-2021-33193Request splitting via HTTP/2 method injection and mod_proxyEPSS 46.2%CVE-2026-21962CRITICALVulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic ServeEPSS 42.7%CVE-2022-22721core: Possible buffer overflow with very large or unlimited LimitXMLRequestBodyEPSS 41.9%CVE-2024-38476CRITICALApache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirectEPSS 41.6%CVE-2021-39275ap_escape_quotes buffer overflowEPSS 39.4%CVE-2017-7679In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious CoEPSS 39.3%CVE-2024-39573HIGHApache HTTP Server: mod_rewrite proxy handler substitutionEPSS 35.4%CVE-2022-22720HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlierEPSS 28.2%CVE-2026-49975HIGHApache HTTP Server: mod_http2 denial of serviceEPSS 28.0%CVE-2024-38473HIGHApache HTTP Server proxy encoding problemEPSS 25.9%CVE-2021-41524null pointer dereference in h2 fuzzingEPSS 25.0%CVE-2016-2161In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continueEPSS 21.0%CVE-2017-3167In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentEPSS 20.2%CVE-2018-17199In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes sessEPSS 20.0%CVE-2017-3169In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_prEPSS 20.0%CVE-2016-4975mod_userdir CRLF injectionEPSS 19.8%