Information disclosure in Apache HTTP Server - CVE-2026-47360
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper session cookie removal in the mod_session_cookie module when SessionCookieRemove changes across internal redirects. A remote attacker can send a request that triggers an internal redirect to disclose sensitive information.
The session cookie may still be passed to a backend server.