Apache2: In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page.
Apache HTTP Server versions 2.4.0 through 2.4.39 contain a limited cross-site scripting (XSS) vulnerability in the mod_proxy error page. This issue allows an attacker to manipulate the link on the error page to redirect users to a malicious page. Exploitation requires that the server has proxying enabled and is misconfigured such that the Proxy Error page is displayed.
AI Analysis
Technical Summary
A limited cross-site scripting vulnerability exists in Apache HTTP Server versions 2.4.0 to 2.4.39 affecting the mod_proxy error page. An attacker can cause the error page's link to be malformed and redirect users to an attacker-controlled page. This vulnerability is only exploitable on servers with proxying enabled and misconfigured to display the Proxy Error page. The issue is documented under Ubuntu advisories for multiple Ubuntu LTS releases, with no known exploits in the wild. No explicit patch information is provided in the input data.
Potential Impact
Successful exploitation could lead to limited cross-site scripting attacks where users viewing the mod_proxy error page may be redirected to attacker-controlled sites. This could result in information disclosure or user redirection but does not impact server availability or integrity. The vulnerability requires specific server proxy configuration and error page display, limiting its scope.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is confirmed, administrators should review proxy configurations to avoid misconfigurations that cause the Proxy Error page to be displayed. Applying updates from the respective Linux distribution vendors (Ubuntu 14.04 LTS, 16.04 LTS, 18.04 LTS) when available is recommended.
Apache2: In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page.
Description
Apache HTTP Server versions 2.4.0 through 2.4.39 contain a limited cross-site scripting (XSS) vulnerability in the mod_proxy error page. This issue allows an attacker to manipulate the link on the error page to redirect users to a malicious page. Exploitation requires that the server has proxying enabled and is misconfigured such that the Proxy Error page is displayed.
CVSS v3.1
Score 6.1medium
Affected software
pkg:deb/ubuntu/[email protected]+esm15?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/[email protected]?arch=source&distro=xenialpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A limited cross-site scripting vulnerability exists in Apache HTTP Server versions 2.4.0 to 2.4.39 affecting the mod_proxy error page. An attacker can cause the error page's link to be malformed and redirect users to an attacker-controlled page. This vulnerability is only exploitable on servers with proxying enabled and misconfigured to display the Proxy Error page. The issue is documented under Ubuntu advisories for multiple Ubuntu LTS releases, with no known exploits in the wild. No explicit patch information is provided in the input data.
Potential Impact
Successful exploitation could lead to limited cross-site scripting attacks where users viewing the mod_proxy error page may be redirected to attacker-controlled sites. This could result in information disclosure or user redirection but does not impact server availability or integrity. The vulnerability requires specific server proxy configuration and error page display, limiting its scope.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is confirmed, administrators should review proxy configurations to avoid misconfigurations that cause the Proxy Error page to be displayed. Applying updates from the respective Linux distribution vendors (Ubuntu 14.04 LTS, 16.04 LTS, 18.04 LTS) when available is recommended.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2019-10092
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:16.04:LTS","Ubuntu:18.04:LTS"]
- Cvss Version
- 3.1
Threat ID: 6a6151309c2644c7f8da7286
Added to database: 07/22/2026, 23:24:32 UTC
Last enriched: 07/23/2026, 00:06:13 UTC
Last updated: 09/10/2026, 19:24:52 UTC
Views: 46
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.