CVE-2024-43204: Apache HTTP Server
High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.
SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker. Requires an unlikely configuration where mod_headers is configured to modify the Content-Type request or response header with a value provided in the HTTP request. Users are recommended to upgrade to version 2.4.64 which fixes this issue.
Affected products
- Apache HTTP Server: from 2.4.0, before 2.4.64 (fixed in 2.4.64)
Published 2025-07-10. Last modified 2026-06-17.