Vulnerability

CVE-2024-38476

CRITICAL 9.8

CVE-2024-38476 is a critical-severity vulnerability (CVSS v3.1 9.8). As of 2026-10-05, 181 498 hosts in our data show software it affects on an open port in at least 15 countries.

Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

Published
2024-07-01
Last modified
2025-11-03
CVSS score
9.8 CVSS v3.1
CVSS vector (v3.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploit likelihood (EPSS)
Not scored

Exposure in our data

181 498 hosts

Hosts whose banner shows an affected software version on a port open at their latest check.

Not counted: 24 977 hosts with this CVE only from an older observation.

Counted 2026-10-05 02:21 UTC

By country

Germany DE44 637
United States US19 071
France FR17 977
Netherlands NL15 994
United Kingdom GB14 363
Italy IT6 315
Finland FI5 659
Poland PL5 118
Czechia CZ4 599
Ireland IE4 559
Spain ES4 194
Lithuania LT3 333
Sweden SE2 493
Japan JP1 979
Switzerland CH1 943

Affected software seen

http_server 2.4.5841 693
http_server 2.4.5228 853
http_server 2.4.4120 576
http_server 2.4.613 772
http_server 2.4.2910 652
http_server 2.4.379 633
http_server 2.4.256 439
http_server 2.4.596 124
http_server 2.4.186 088
http_server 2.4.385 742
http_server 2.4.105 231
http_server 2.4.73 349