critical
CVE-2024-38475
Apache mod_rewrite improper substitution escaping - source disclosure and code execution via crafted URLs
- Severity
- critical
- Affected product
- Apache httpd
- Affected versions
- Apache httpd ≥ 2.4.0, < 2.4.60
- Fixed in
- Apache httpd 2.4.60
- Added to NewScan
- 2026-08-02
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Apache httpd from its response and reports this CVE when the detected version falls inside the affected range below.
Backfilled 2026-08-02 (docs/todo.md item 1).
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →