Reporting Security Problems with Apache - The Apache HTTP Server Project
Essentials
Download!
About
License
FAQ
Security Reports
Source Repositories
General Information
Trunk
2.4
Documentation
Version 2.4
Trunk (dev)
Wiki
Get Involved
Mailing Lists
Bug Reports
Developer Info
User Support
Subprojects
Docs
Test
Flood
libapreq
Modules
mod_fcgid
mod_ftp
Related Projects
Apache Traffic Server
Apache Traffic Control
Tomcat
APR
mod_perl
Miscellaneous
Contributors
Thanks!
Sponsorship
Security Updates
Lists of security problems fixed in released versions of the Apache HTTP
Server are available:
Apache 2.4 Security Vulnerabilities
To get notification of when new security issues are fixed, join the
Apache
HTTP Server Announcements
list
Reporting New Security Problems with the Apache HTTP Server
The Apache Software Foundation takes a very active stance in eliminating
security problems and denial of service attacks against the Apache HTTP
server.
We strongly encourage folks to report such problems to the private security
mailing list of the ASF Security Team, before disclosing them in a public
forum.
Please see the page of the
ASF Security
Team
for further information and contact
information.
The Security Team cannot accept regular bug reports or other queries, we
ask that you use our
bug reporting page
for
those.
All mail sent to the Security Team that does
not relate to security problems in Apache software will be
ignored.
Note that all networked servers are subject to denial of service attacks,
and we cannot promise magic workarounds to generic problems (such as a
client streaming lots of data to your server, or re-requesting the same URL
repeatedly). In general our philosophy is to avoid any attacks which can
cause the server to consume resources in a non-linear relationship to the
size of inputs.
More security
tips
Security Standards
Apache HTTP Server vulnerabilities are labelled with
CVE
(Common Vulnerabilities and Exposures)
identifiers.
Historical Releases
Earlier versions of Apache HTTP Server are no longer receiving security
updates and should not be used.
Apache 2.2 Historical Security Vulnerabilities (2005-2017)
Apache 2.0 Historical Security Vulnerabilities (2002-2013)
Apache 1.3 Historical Security Vulnerabilities (1998-2010)
Copyright © 1997-2026 The Apache Software Foundation.
Apache HTTP Server, Apache, the Apache logo and the Apache HTTP Server logo are
either registered trademarks or trademarks of The Apache Software Foundation in the United States
and other countries.