CVE-2026-42356
CVE-2026-42356: 2 tracked advisory records across Apache, Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Apache
1 advisory- Advisory severityLow3.7
Low [CVE-2026-42356] Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed
CVE-2026-42356Source published Source updated
Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.
- Affected products in this advisory
- Apache HTTP Server
- Source-reported affected versions
- 2.4.60 through 2.4.68.
- through 2.4.68
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Red Hat
1 advisory- Advisory severityLow3.7
Low [CVE-2026-42356] arbitrary code execution via incorrect handler assignment during internal CGI redirects
CVE-2026-42356Source published Source updated
arbitrary code execution via incorrect handler assignment during internal CGI redirects. Red Hat rates this low (CVSS 3.7). Weakness: CWE-430. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: httpd.
- Related products — impact not confirmed
- Red Hat Hardened Images
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat package: httpd
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- httpd-main-2.4.69-1.hum1
- RHSA-2026:74858
- Mitigation guidance
- If CGI functionality is not required, disable CGI execution by commenting out `mod_cgi` or `mod_cgid` in the Apache configuration (for example, in `/etc/httpd/conf.modules.d/01-cgi.conf`), or by removing `ExecCGI` from `Options` directives in `/etc/httpd/conf/httpd.conf`. Apply the changes to the running service: systemctl reload httpd Caveats: Disabling CGI modules or execution options will prevent any existing CGI applications from functioning. Warning: Reloading or restarting the httpd service may temporarily disrupt active connections.
Android app · Google Play
Turn CVE research into alerts on your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.