CVE-2026-42356(apache / http_server)

LOWCVSS 3.7 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-430

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • http_server

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
http_server

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-02: 110-02
Referenced assets1 URL
By indicator
Full discourse1 post
  • Rıdvan Yağlı@ridvanyagli

    🔴 Apache HTTP Server 2.4.69 yayınlandı. Güncelleme, 2.4.68 ve öncesini etkileyen 20 güvenlik açığını gideriyor. Öne çıkan önemli açıklar: • CVE-2026-63292: mod_vhost_alias — DoS ve koşullu kod çalıştırma • CVE-2026-42356: CGI handler — sınırlı kod çalıştırma • CVE-2026-57941: mod_http2 — UAF / bellek yazma • CVE-2026-93546: mod_dav_fs — crash ve veritabanı bozulması Açıkların çoğu Moderate/Low seviyede ve sömürülebilirlik yapılandırmaya bağlı. Apache 2.4.69'a güncellemeyi düşünün. https://www.apachelounge.com/changelog-2.4.html

    00010152
    2.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachehttp_server---

Explore more