Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-42356

Опубликовано: 01 окт. 2026
Источник: debian

Описание

Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apache2fixed2.4.69-1package

Примечания

  • https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-42356

  • Fixed by: https://github.com/apache/httpd/commit/863594b37381151c397b9fbc609170d026411614

Связанные уязвимости

CVSS3: 3.7
redhat
2 дня назад

A flaw was found in Apache HTTP Server. An attacker could achieve unintended code execution when an internal redirect generated by a Common Gateway Interface (CGI) program points to a non-executable file. If the target file resides in a directory configured for CGI execution and lacks a file extension recognized by the MIME handler, the server incorrectly treats and executes the target file as a script. This issue could allow an attacker to run unauthorized commands or code within the server context.

CVSS3: 3.7
nvd
2 дня назад

Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.

CVSS3: 3.7
github
2 дня назад

Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.