CVE-2019-0220: Apache HTTP Server

Medium severity, CVSS 5.3. EPSS: 18% chance of exploitation in the next 30 days.

A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions while other aspects of the servers processing will implicitly collapse them.

Affected products

  • Apache HTTP Server: from 2.4.0, up to and including 2.4.38
  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Fedoraproject Fedora: version 28 only; version 29 only; version 30 only
  • Opensuse Leap: version 15.0 only; version 42.3 only

Published 2019-06-11. Last modified 2026-06-17.