Skip to content
COOEY

FAIL › dossier

HTTP Server

PRODUCT

· dossier confidence 33%

Apache HTTP Server, a widely used web server, has a history of critical security vulnerabilities including remote code execution and denial-of-service issues, requiring careful management and timely patching to mitigate risk. The software's open-source nature and widespread adoption make it a frequent target for attackers.

PROFILE
CategoryWeb Server SoftwareWhat they doApache HTTP Server is a widely used web server software known for its reliability and flexibility. It serves static content and can be extended with modules to handle dynamic content and other functionalities. Websitehttps://httpd.apache.org/ ↗
SECURITY POSTURE

Apache HTTP Server has a history of critical security vulnerabilities, including remote code execution and denial-of-service issues, indicating a need for diligent patching and security practices.

Notable failures
  • CVE-2024-38475 (RCE) - mod_rewrite vulnerability
  • CVE-2021-42013 (RCE) - Path traversal vulnerability exploited in ransomware
  • CVE-2021-41773 (RCE) - Inadequate patch for path traversal vulnerability
  • CVE-2019-0211 (RCE) - Code execution in less-privileged processes
  • CVE-2026-8856 (DoS) - Denial of service in IBM HTTP Server configuration
  • CVE-2026-8855 (RCE/DoS) - Remote code execution and denial of service in IBM HTTP Server
Patterns: Recurring remote code execution vulnerabilities; Inadequate patching leading to exploitation; Vulnerabilities impacting IBM HTTP Server
FAILURE HISTORY · 7
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2019-0211 high Apache HTTP Server allowed privilege escalation to root via scoreboard manipulation, enabling attackers to execute arbitrary code as the parent process.
2025-05-01 CVE-2024-38475 high Apache HTTP Server's mod_rewrite module has a vulnerability allowing attackers to potentially execute code or disclose source code via improper output escaping, and is currently being actively exploited in the wild.
2021-11-03 CVE-2021-42013 critical An incomplete Apache HTTP Server patch left systems vulnerable to remote code execution via path traversal, actively exploited in ransomware attacks and impacting NIST 800-171 compliance efforts.
2021-11-03 CVE-2021-41773 critical Apache HTTP Server's path traversal vulnerability allowed remote code execution, and the initial patch was inadequate, demonstrating a failure to properly secure web server configurations and remediate vulnerabilities effectively.
2026-05-26 CVE-2026-8856 high CVE-2026-8856: IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configuration
2026-05-26 CVE-2026-8855 high CVE-2026-8855: IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial o
2021-09-16 CVE-2021-40438 critical CVE-2021-40438: A crafted request uri-path can cause mod_proxy to forward the request to an orig
Open questions: What is the current patching status of Apache HTTP Server and IBM HTTP Server? · What security controls are in place to prevent exploitation of known vulnerabilities? · What is the relationship between Apache HTTP Server and IBM HTTP Server?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-28 12:39:28.896755+00:00