CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-48005: http server from 2.4.0 (inclusive), before 2.4.69 (exclusive); +1 more affected products

CVE-2026-48005. CVSS 3.1 base score 7.5 (HIGH, Source advisory). EPSS 0.00606 (percentile 0.47164), scored 2026-10-05.

Affected technology

http server · from 2.4.0 (inclusive), before 2.4.69 (exclusive)
apache

Apache HTTP Server · 2.4.0 through 2.4.68
Apache Software Foundation

Description’s affected range: before 2.4.69 on all platforms

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

The source reports that an attacker could disrupt service under the conditions described by the source. Source advisory’s CVSS 3.1 assessment (base score 7.5/10) rates confidentiality and integrity impact as none; availability impact as high.

Published

CWE
CWE-306
CCR priority
30.2 /100 (P4)
CVSS 3.1
7.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H · Source advisory
EPSS
0.00606 · percentile 0.47164 · 2026-10-05
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-48005.html