Apache Software FoundationCVE-2026-42356
Deployment of wrong handler vulnerability in Apache HTTP Server
Low3.7CVE-2026-42356 · Published Oct 1, 2026 · updated Oct 6, 2026
Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Apache HTTP Server Product | >= 2.4.60, <= 2.4.68 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-430
More Apache Software Foundation advisories
All Apache Software Foundation| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 1 | Apache HTTP Server: integer overflow | High8.8 | No fix yet |
| Oct 1 | Apache HTTP Server: use after free | High7.3 | No fix yet |
| Oct 1 | Path equivalence: '/./' | Medium5.3 | No fix yet |
| Oct 1 | Apache HTTP Server: request smuggling | High7.5 | No fix yet |
| Oct 1 | Apache HTTP Server: authentication bypass | High8.1 | No fix yet |
| Oct 1 | Apache HTTP Server: exposed files | Medium5.3 | No fix yet |