Interpretation Conflict in Apache HTTP Server - CVE-2026-42356
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to incorrect handler deployment in Apache HTTP Server when processing internal redirects from CGI programs to non-CGI files in CGI-enabled directories. A remote attacker can trigger an internal redirect from a CGI program to execute arbitrary code.
The target file must not have an extension understood by mod_mime.