FAIL › dossier
HTTP Server
PRODUCT· dossier confidence 33%
Apache HTTP Server, a widely used web server, has a history of critical security vulnerabilities including remote code execution and denial-of-service issues, requiring careful management and timely patching to mitigate risk. The software's open-source nature and widespread adoption make it a frequent target for attackers.
PROFILE
CategoryWeb Server SoftwareWhat they doApache HTTP Server is a widely used web server software known for its reliability and flexibility. It serves static content and can be extended with modules to handle dynamic content and other functionalities.
Websitehttps://httpd.apache.org/ ↗
SECURITY POSTURE
Apache HTTP Server has a history of critical security vulnerabilities, including remote code execution and denial-of-service issues, indicating a need for diligent patching and security practices.
Notable failures
- CVE-2024-38475 (RCE) - mod_rewrite vulnerability
- CVE-2021-42013 (RCE) - Path traversal vulnerability exploited in ransomware
- CVE-2021-41773 (RCE) - Inadequate patch for path traversal vulnerability
- CVE-2019-0211 (RCE) - Code execution in less-privileged processes
- CVE-2026-8856 (DoS) - Denial of service in IBM HTTP Server configuration
- CVE-2026-8855 (RCE/DoS) - Remote code execution and denial of service in IBM HTTP Server
Patterns: Recurring remote code execution vulnerabilities; Inadequate patching leading to exploitation; Vulnerabilities impacting IBM HTTP Server
FAILURE HISTORY · 7
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2019-0211 | high | Apache HTTP Server allowed privilege escalation to root via scoreboard manipulation, enabling attackers to execute arbitrary code as the parent process. |
| 2025-05-01 | CVE-2024-38475 | high | Apache HTTP Server's mod_rewrite module has a vulnerability allowing attackers to potentially execute code or disclose source code via improper output escaping, and is currently being actively exploited in the wild. |
| 2021-11-03 | CVE-2021-42013 | critical | An incomplete Apache HTTP Server patch left systems vulnerable to remote code execution via path traversal, actively exploited in ransomware attacks and impacting NIST 800-171 compliance efforts. |
| 2021-11-03 | CVE-2021-41773 | critical | Apache HTTP Server's path traversal vulnerability allowed remote code execution, and the initial patch was inadequate, demonstrating a failure to properly secure web server configurations and remediate vulnerabilities effectively. |
| 2026-05-26 | CVE-2026-8856 | high | CVE-2026-8856: IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configuration |
| 2026-05-26 | CVE-2026-8855 | high | CVE-2026-8855: IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial o |
| 2021-09-16 | CVE-2021-40438 | critical | CVE-2021-40438: A crafted request uri-path can cause mod_proxy to forward the request to an orig |
DOSSIER SOURCES
- GoDaddy - Wikipedia · en.wikipedia.org
- Cisco - Wikipedia · en.wikipedia.org
- HTTP Server: Releases, patches & end-of-life - versio.io · www.versio.io
- HTTP Server Security Vulnerability: Please upgrade to 0.6.17 · nodejs.org
- HTTP Server: Releases, patches & end-of-life - versio.io · www.versio.io
- HTTP Server: Releases, patches & end-of-life - versio.io · www.versio.io
- Apache Http Server End of Life (EOL) Date - Version Support Schedule · eoldate.com
Open questions: What is the current patching status of Apache HTTP Server and IBM HTTP Server? · What security controls are in place to prevent exploitation of known vulnerabilities? · What is the relationship between Apache HTTP Server and IBM HTTP Server?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-28 12:39:28.896755+00:00