← volver
CVE-2026-42356lowCWE-430

Apache HTTP Server: limited RCE for some internal redirects to non-CGI files in CGI directories

8Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 3.7epss 0.2%
probabilidad de explotación
0.2%top 88% de las CVE
explotación observada
noninguna fuente lo reporta
Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N