apache http-server CVE-2026-59797 is a vulnerability in Apache HTTP Server
Published on October 1, 2026

Apache HTTP Server: mod_ssl SSLRequire allows .htaccess ap_expr file-function
Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Vendor Advisory NVD

Timeline

reported

fixed in 2.4.x by r1938672 95 days later.

2.4.69 released

Weakness Type

Improper Privilege Management

The software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.


Products Associated with CVE-2026-59797

Want to know whenever a new CVE is published for Apache HTTP Server? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache HTTP Server: