CVE-2024-38475
CWE-116
99.6
RPSRPS range: 0–105; KEV-listed vulnerabilities can receive an exploitation amplifier.
Description
Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected. Some unsafe RewiteRules will be broken by this change and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained.
Source: NVD
Signals
- CVSS
- 9.1
- Critical · v3.1
- EPSS
- 99.95%
- Probability of exploitation in the next 30 days (FIRST)
- CISA KEV
- In CISA KEV since May 2025
- Fix commit
- No known fix commit
- Sources: MoreFixes, FreshFixes
- Weakness
- CWE-116
- Published
- 1 Jul 2024
- Last modified 17 Nov 2025
How to read these signals: RPS · EPSS · CISA KEV · Data sources
Get this score from the API
curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
https://api.intelligence.devsecure.io/api/v1/rps/CVE-2024-38475Replace the placeholder with your key. Get a free API key or rank your own CVEs.
Data as of 7 Oct 2026, 05:16 UK time