Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.
Conclusion & alert: CVE-2024-38474 is rated High Risk (69.7/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 2.46%). Core evidence: EPSS rose +1.73% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.73% | 2.46% | +1.73% |
| 2 | 2026-06-11 | 0.99% | 0.73% | -0.27% |
| 3 | 2026-04-14 | — | 0.99% | — |
Full EPSS history (54 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 8.1 | 3.1 | HIGH |
|
2.8 | 5.2 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2024-38474: 1 source package rows (apache2); 7 state rows across 7 repos (3.17-main, 3.18-main, 3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-main); fixed 7, open 0. | https://security.alpinelinux.org/vuln/CVE-2024-38474 |
debian
|
not yet assigned | CVE-2024-38474 not yet assigned priority: Debian including 1 source packages (apache2), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2024-38474 |
gentoo
|
low | CVE-2024-38474: 1 GLSA(s) (202409-31), 1 atom(s) (www-servers/apache); latest impact low. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2024-38474 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2024-38474 |
suse
|
high | CVE-2024-38474 severity important: SUSE including 324 source package names (2.8:apache2-utils-2.4.58-150600.5.23.1, 4.3.13.9.57.26:apache2-2.4.51-150400.6.34.1, …), 541 product×package rows across 78 product lines (Container bci/php-apache, Container suse/manager/4.3/proxy-httpd, … (78 product lines)): Fixed 309, Known Affected 231, Known Not Affected 1. | https://www.suse.com/security/cve/CVE-2024-38474/ |
ubuntu
|
medium | CVE-2024-38474 medium priority: Ubuntu including 1 source packages (apache2), 10 status rows across 10 suites (bionic, focal, jammy, mantic, noble, oracular, plucky, trusty, upstream, xenial): released 10. | https://ubuntu.com/security/CVE-2024-38474 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | http_server | >= 2.4.0, < 2.4.60 | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* |
| netapp | clustered_data_ontap | 9.0 | cpe:2.3:o:netapp:clustered_data_ontap:9.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://httpd.apache.org/security/vulnerabilities_24.html | Vendor Advisory |
| https://security.netapp.com/advisory/ntap-20240712-0001/ | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2024/07/01/7 |