CVE-2026-47360: Apache HTTP Server: mod_session: Session cookie not removed during internal redirect
Published Oct 1, 2026
·Updated
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's modsessioncookie module.
When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Affected Software
1 affected component
Apache HTTP Server>=2.4.0<=2.4.68
Event History
Oct 1, 2026
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness