CVE-2026-79768
Apache HTTP Server: mod_userdir information disclosure
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
| CWE | CWE-55 |
| Vendor | apache software foundation |
| Product | apache http server |
| Published | Oct 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache http server
Be the first to know when new unknown vulnerabilities affecting apache software foundation apache http server are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Apache Software Foundation / Apache HTTP Server
2.4.0 ≤ 2.4.68
References
Credits
Vlatko Kosturjak, Marlink Cyber