← Back to browse · API

CVE-2024-38476

Severity
CRITICAL
CVSS
9.8
EPSS
0.41611
Risk score
53.76
CISA KEV
No
PoC
No
Published
2024-07-01
Modified
2025-11-03
First seen
2026-08-07
Aliases
EUVD-2024-37357, GHSA-FPQ9-W5CW-5HF8
Products
Apache Software Foundation:Apache HTTP Server 2.4.0 ≤2.4.59
Sources
euvd EUVD-2024-37357

Description

Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

References