USN-8571-1: Apache HTTP Server vulnerabilities
Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server incorrectly handled certain memory operations in mod_authn_socache. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-33007) Haruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache HTTP Server had an HTTP response splitting vulnerability in multiple modules when used with untrusted or compromised backend servers. An attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2026-33523) Elhanan Haenel discovered that Apache HTTP Server incorrectly handled certain memory operations in mod_proxy_ajp. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-33857) Tianshuo Han and Jérôme Djouder discovered that Apache HTTP Server incorrectly handled certain string operations in mod_proxy_ajp. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-34032) It was discovered that Apache HTTP Server's mod_proxy_html module incorrectly handled certain content from an untrusted backend. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-34355) It was discovered that Apache HTTP Server incorrectly handled ProxyPassReverseCookie directives with a malicious backend server. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-34356) It was discovered that Apache HTTP Server's mod_dav_fs module incorrectly handled certain path operations. An authenticated user could possibly use this issue to manipulate trusted WebDAV property databases or cause a denial of service. (CVE-2026-42535) It was discovered that Apache HTTP Server's mod_xml2enc module incorrectly handled certain content from an untrusted backend. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-42536) It was discovered that Apache HTTP Server incorrectly handled response headers when multiple content language
CSIRTS triage
- What
- Apache HTTP Server has multiple vulnerabilities that could lead to denial of service or HTTP header injection.
- Who is affected
- Deployments of Apache HTTP Server using affected modules.
- Urgency
- Immediate remediation is required due to the potential for denial of service and security risks.
- Action
- Upgrade to the latest version of Apache HTTP Server to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Apache HTTP Server
Get an email when a new Apache HTTP Server advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8571-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-330070.51% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all scored CVEs.
- Low exploitation riskCVE-2026-335230.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all scored CVEs.
- Low exploitation riskCVE-2026-338570.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all scored CVEs.
- Low exploitation riskCVE-2026-340320.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all scored CVEs.
- Moderate exploitation riskCVE-2026-343551.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 63% of all scored CVEs.
- Low exploitation riskCVE-2026-343560.71% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all scored CVEs.
- Low exploitation riskCVE-2026-425350.54% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all scored CVEs.
- Low exploitation riskCVE-2026-425360.99% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 59% of all scored CVEs.
- Low exploitation riskCVE-2026-439510.55% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all scored CVEs.
- Low exploitation riskCVE-2026-441190.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-33007 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-33523 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-33857 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34032 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34355 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34356 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42535 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42536 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-43951 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44119 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44185 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44186 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44631 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48913 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Oracle Solaris third-party components: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Apache HTTP Server: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Apache HTTP Server: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Tenable Security Center (July 21, 2026)cert-fr-avis
- unknownUSN-8516-1: Apache HTTP Server vulnerabilitiesubuntu
- highCVE-2026-34356: Apache HTTP Server: ProxyPassReverseCookieMap buffer overflowmsrc
- highCVE-2026-42536: Apache HTTP Server: mod_xml2enc heap overflowmsrc
- mediumCVE-2026-44119: Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modul…msrc
- mediumCVE-2026-44186: Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftpmsrc
- highCVE-2026-34355: Apache HTTP Server: mod_proxy_html buffer overflowmsrc
- criticalCVE-2026-44631: Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflowmsrc
- highCVE-2026-48913: Apache HTTP Server: mod_http2 memory corruption when file handles exhaustedmsrc
More from Ubuntu Security Notices
- highUSN-8620-4: Linux kernel (Intel IoTG) vulnerabilities2026-07-31
- highUSN-8620-3: Linux kernel (Intel IoTG) vulnerabilities2026-07-31
- unknownUSN-8625-1: OpenSSL vulnerability2026-07-30
- unknownUSN-8624-1: Sinatra vulnerability2026-07-29
- unknownUSN-8623-1: Linux kernel (NVIDIA) vulnerabilities2026-07-29