CVE-2026-59797: Apache HTTP Server: mod_ssl SSLRequire allows .htaccess ap_expr file-function
Published Oct 1, 2026
·Updated
Improper Privilege Management vulnerability in Apache HTTP Server's modssl via SSLRequire and file-related expressions.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Affected Software
1 affected component
Apache HTTP Server>=2.4.0<=2.4.68
Event History
Oct 1, 2026
CVE Published
via MITRE·04:08 PM
Data Sourced
via MITRE·04:08 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Apache HTTP Server versions should be treated as affected?
Apache HTTP Server versions 2.4.0 through 2.4.68 are identified as affected.
2
Is a fixed release or workaround identified in the provided information?
No fixed release or mitigation is specified in the provided information.