Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42356

Опубликовано: 01 окт. 2026
Источник: redhat
CVSS3: 3.7

Описание

A flaw was found in Apache HTTP Server. An attacker could achieve unintended code execution when an internal redirect generated by a Common Gateway Interface (CGI) program points to a non-executable file. If the target file resides in a directory configured for CGI execution and lacks a file extension recognized by the MIME handler, the server incorrectly treats and executes the target file as a script. This issue could allow an attacker to run unauthorized commands or code within the server context.

Меры по смягчению последствий

If CGI functionality is not required, disable CGI execution by commenting out mod_cgi or mod_cgid in the Apache configuration (for example, in /etc/httpd/conf.modules.d/01-cgi.conf), or by removing ExecCGI from Options directives in /etc/httpd/conf/httpd.conf. Apply the changes to the running service: systemctl reload httpd Caveats: Disabling CGI modules or execution options will prevent any existing CGI applications from functioning. Warning: Reloading or restarting the httpd service may temporarily disrupt active connections.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10httpdFix deferred
Red Hat Enterprise Linux 6httpdNot affected
Red Hat Enterprise Linux 7httpdNot affected
Red Hat Enterprise Linux 8httpd:2.4/httpdNot affected
Red Hat Enterprise Linux 9httpdFix deferred
Red Hat Hardened Imageshttpd-main-2.4.69-1.hum1FixedRHSA-2026:7485802.10.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-430
https://bugzilla.redhat.com/show_bug.cgi?id=2544825httpd: httpd: arbitrary code execution via incorrect handler assignment during internal CGI redirects

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
nvd
2 дня назад

Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.

CVSS3: 3.7
debian
2 дня назад

Deployment of wrong handler vulnerability in Apache HTTP Server allows ...

CVSS3: 3.7
github
2 дня назад

Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.

3.7 Low

CVSS3