Skip to content
Apache HTTP Server Regression Vulnerability Disclosed

Apache HTTP Server Regression Vulnerability Disclosed

First seen 11 Sep 2026, 04:46 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 11, 2026 at 07:17 UTC

A regression in Apache HTTP Server was introduced by USN-8571-1, which failed to fully address vulnerabilities, leading to potential denial of service when HTTP/2 proxying is enabled. The vulnerabilities include CVE-2026-33007, which allows remote attackers to exploit memory operations, and CVE-2026-33523, which enables HTTP response splitting. The affected systems include Ubuntu 20.04 LTS running Apache2. The update, USN-8571-2, released on September 10, 2026, aims to fix the regression. Administrators are advised to update their systems to mitigate these vulnerabilities. The issue affects users who rely on Apache HTTP Server with HTTP/2 proxying enabled. The vulnerabilities were discovered by multiple researchers, highlighting the collaborative nature of security research.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-05-04
CVE-2026-33007 published
Memory operation vulnerabilities in Apache HTTP Server could lead to denial of service.
Ubuntu
2026-05-04
CVE-2026-33523 published
HTTP response splitting vulnerability discovered in Apache HTTP Server affecting multiple modules.
Ubuntu
2026-05-04
CVE-2026-34032 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-04
CVE-2026-33857 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-08
CVE-2026-42535 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-08
CVE-2026-34356 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-08
CVE-2026-44119 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-08
CVE-2026-44186 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-08
CVE-2026-34355 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-08
CVE-2026-43951 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (2)

Following this threat?

Track Ubuntu and CVE-2026-33007 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed