🛡️ USN-8338-1 — apache2

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

apache2 vulnerabilities

It was discovered that Apache HTTP Server incorrectly handled certain

response headers. An attacker could possibly use this issue to perform

HTTP response splitting attacks. This issue only affected Ubuntu 14.04

LTS. (CVE-2023-38709)

Will Dormann and David Warren discovered that Apache HTTP Server's HTTP/2

implementation did not properly reclaim memory when streams were reset by

clients. A remote attacker could possibly use this issue to cause Apache

HTTP Server to consume resources, leading to a denial of service. This

issue only affected Ubuntu 18.04 LTS. (CVE-2023-45802)

Keran Mu and Jianjun Chen discovered that Apache HTTP Server incorrectly

handled certain response headers. An attacker could possibly use this issue

to perform HTTP response splitting attacks. This issue only affected Ubuntu

14.04 LTS. (CVE-2024-24795)

Orange Tsai discovered that Apache HTTP Server mod_proxy incorrectly

handled URL encoding. A remote attacker could possibly use this issue to

bypass authentication via crafted requests. This issue only affected

Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-38473)

Orange Tsai discovered that Apache HTTP Server could be caused to perform

server-side request forgery (SSRF) via malicious backend response headers.

A remote attacker could possibly use this issue to conduct SSRF attacks or

disclose sensitive information. This issue only affected Ubuntu 14.04 LTS.

(CVE-2024-38476)

Orange Tsai discovered that Apache HTTP Server mod_proxy did not properly

handle certain null pointer conditions. A remote attacker could possibly use this

issue to cause Apache HTTP Server to crash, resulting in a denial of

service. This issue only affected Ubuntu 14.04 LTS. (CVE-2024-38477)

Orange Tsai discovered that Apache HTTP Server mod_rewrite could be made

to perform server-side request forgery (SSRF) via unsafe RewriteRules. A

remote attacker could possibly use this issue to conduct SSRF attacks. This

issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-39573)

It was discovered that Apache HTTP Server incorrectly handled certain

response headers. An attacker could possibly use this issue to perform

HTTP response splitting attacks. This issue only affected Ubuntu 14.04 LTS.

(CVE-2024-42516)

It was discovered that Apache HTTP Server could be caused to perform

server-side request forgery (SSRF) via mod_headers modifying Content-Type

headers. A remote attacker could possibly use this issue to conduct SSRF

attacks. This issue only affected Ubuntu 14.04 LTS. (CVE-2024-43204)

John Runyon discovered that Apache HTTP Server mod_ssl did not properly

escape user-supplied data before writing log entries. A remote attacker

could possibly use this issue to insert escape sequences into log files.

This issue only affected Ubuntu 14.04 LTS. (CVE-2024-47252)

Robert Merget discovered that Apache HTTP Server with SSLEngine optional was

vulnerable to HTTP desynchronisation attacks. An attacker in a privileged

network position could possibly use this issue to hijack HTTP sessions. This issue

only affected Ubuntu 14.04 LTS. (CVE-2025-49812)

It was discovered that Apache HTTP Server mod_md had an integer overflow in

the ACME certificate renewal backoff timer. An attacker could possibly use

this issue to cause excessive certificate renewal requests. This issue only

affected Ubuntu 20.04 LTS. (CVE-2025-55753)

Anthony Parfenov discovered that Apache HTTP Server with SSI enabled and

mod_cgid passed shell-escaped query strings to #exec cmd directives. A

remote attacker could possibly use this issue to perform command injection.

(CVE-2025-58098)

Mattias Åsander discovered that Apache HTTP Server incorrectly gave

precedence to environment variables from HTTP headers over server-calculated

CGI variables. A remote attacker could possibly use this issue to influence

the environment of CGI programs. (CVE-2025-65082)

Mattias Åsander discovered that Apache HTTP Server mod_userdir with suexec

could be caused to run CGI scripts under an unexpected user ID via

RequestHeader directives in .htaccess files. An attacker with .htaccess

write access could possibly use this issue to bypass suexec user restrictions.

(CVE-2025-66200)

Affected software

USN-8338-1 is recorded against 1 package.

  • apache2 (fixed in 2.4.41-4ubuntu3.23+esm3)

Timeline and source

Published on 28 May 2026 and last revised on 29 May 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

ubuntu.com (Advisory)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-05-28
Updated 2026-08-12
Modified 2026-05-29
Fix URL N/A

Affected Packages

Software From version Fixed in
apache2 2.4.41-4ubuntu3.23+esm3

References

Free Vulnerability Check

Is your site affected by USN-8338-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against USN-8338-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.