Vulnerability
CVE-2024-38476
CRITICAL 9.8
CVE-2024-38476 is a critical-severity vulnerability (CVSS v3.1 9.8). As of 2026-10-05, 181 498 hosts in our data show software it affects on an open port in at least 15 countries.
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
- Published
- 2024-07-01
- Last modified
- 2025-11-03
- CVSS score
- 9.8 CVSS v3.1
- CVSS vector (v3.1)
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploit likelihood (EPSS)
- Not scored
Exposure in our data
181 498 hosts
Hosts whose banner shows an affected software version on a port open at their latest check.
Not counted: 24 977 hosts with this CVE only from an older observation.
Counted 2026-10-05 02:21 UTC
By country
| Germany DE | 44 637 |
| United States US | 19 071 |
| France FR | 17 977 |
| Netherlands NL | 15 994 |
| United Kingdom GB | 14 363 |
| Italy IT | 6 315 |
| Finland FI | 5 659 |
| Poland PL | 5 118 |
| Czechia CZ | 4 599 |
| Ireland IE | 4 559 |
| Spain ES | 4 194 |
| Lithuania LT | 3 333 |
| Sweden SE | 2 493 |
| Japan JP | 1 979 |
| Switzerland CH | 1 943 |
Affected software seen
| http_server 2.4.58 | 41 693 |
| http_server 2.4.52 | 28 853 |
| http_server 2.4.41 | 20 576 |
| http_server 2.4.6 | 13 772 |
| http_server 2.4.29 | 10 652 |
| http_server 2.4.37 | 9 633 |
| http_server 2.4.25 | 6 439 |
| http_server 2.4.59 | 6 124 |
| http_server 2.4.18 | 6 088 |
| http_server 2.4.38 | 5 742 |
| http_server 2.4.10 | 5 231 |
| http_server 2.4.7 | 3 349 |