Apache Software Foundation Apache HTTP Server 2.4.63

CPE Details

Apache Software Foundation Apache HTTP Server 2.4.63
2.4.63
2025-08-12
19h22 +00:00
2025-08-12
19h22 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:apache:http_server:2.4.63:*:*:*:*:*:*:*

Informations

Vendor

apache

Product

http_server

Version

2.4.63

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-53020 2025-07-10 15h15 +00:00 Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.
7.5
High
CVE-2025-49812 2025-07-10 15h15 +00:00 In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upgrades are affected. Users are recommended to upgrade to version 2.4.64, which removes support for TLS upgrade.
7.4
High
CVE-2025-49630 2025-07-10 15h15 +00:00 In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".
7.5
High