Apache HTTPD 2.4.0-2.4.68 mod_session_cookie Redirect Cookie Leak
CVE-2026-47360 Published on October 1, 2026
Apache HTTP Server: mod_session: Session cookie not removed during internal redirect
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.
When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Timeline
reported
fixed in 2.4.x by r1938656 139 days later.
2.4.69 released
Weakness Type
What is an Information Disclosure Vulnerability?
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVE-2026-47360 has been classified to as an Information Disclosure vulnerability or weakness.
Products Associated with CVE-2026-47360
Want to know whenever a new CVE is published for Apache HTTP Server? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache HTTP Server:- Version 2.4.0, <= 2.4.68 is affected.