← Back to browse · API

CVE-2024-38473

Severity
HIGH
CVSS
8.1
EPSS
0.25878
Risk score
41.46
CISA KEV
No
PoC
Yes
Published
2024-07-01
Modified
2025-02-13
First seen
2026-08-07
Aliases
EUVD-2024-37354, GHSA-HRH5-4FFC-228Q
Products
Apache Software Foundation:Apache HTTP Server 2.4.0 ≤2.4.59, linux, suse, ubuntu
Sources
packetstorm 6ed36f584bdbf7e8f0001469|CVE-2024-38473
euvd EUVD-2024-37354
packetstorm 2767909aab882d9e4df12f78|CVE-2024-38473
packetstorm e49906dcf3a7c469bcbca014|CVE-2024-38473

Description

Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

References