Security advisories in the AI and data stack

Severe, 6 weeks2979Projects319

Deployment of wrong handler vulnerability in Apache HTTP Server

Low3.7CVE-2026-42356 · Published Oct 1, 2026 · updated Oct 6, 2026

Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.

Affected versions

PackageAffectedFixed in
Apache HTTP Server
Product
>= 2.4.60, <= 2.4.68No fix yet
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache HTTP Server: integer overflow
High8.8Oct 1
Apache HTTP Server: use after free
High7.3Oct 1
Path equivalence: '/./'
Medium5.3Oct 1
Apache HTTP Server: request smuggling
High7.5Oct 1
Apache HTTP Server: authentication bypass
High8.1Oct 1
Apache HTTP Server: exposed files
Medium5.3Oct 1