# CVE-2024-38476

## Summary

- **CVE ID:** CVE-2024-38476
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-829
- **Published:** Jul 1, 2024
- **Last Modified:** Sep 17, 2026

## Description

Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.

Users are recommended to upgrade to version 2.4.60, which fixes this issue.

## Affected Products

- Apache Software Foundation — Apache HTTP Server (2.4.0)

## References

- [CNA](https://httpd.apache.org/security/vulnerabilities_24.html)
- [CNA](https://security.netapp.com/advisory/ntap-20240712-0001/)
- [CVE](http://www.openwall.com/lists/oss-security/2024/07/01/9)
- [CVE](http://seclists.org/fulldisclosure/2024/Oct/11)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 41.61%
- **EPSS Percentile:** 98.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._