PT-2026-103922 · Apache · Apache Http Server

·

CVE-2026-42356

·

Publicado

2026-10-01

·

Atualizado

2026-10-01

CVSS v3.1

3.7

Baixa

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod mime.
This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-42356

Produtos afetados

Apache Http Server