CVE-2026-47360

🟡 Monitoruj

Ujawnienie wrażliwych informacji w Apache HTTP Server pozwala na przekazanie ciasteczka sesji do serwera backendowego.

CVSS
7.5
EPSS
0.4%
Exploit
none
Vendor
apache
Opis źródłowy (NVD)

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.   When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.4%
Opublikowano (NVD)2026-10-01 16:17:44 UTC
Ostatnia modyfikacja (NVD)2026-10-02 20:57:52 UTC
Referencje