CVE WATCH / VULNERABILITY DETAIL
CVE-2026-47360
HIGHCVSS 7.5NVD feed
Published 1 October 2026 · tracked since 2 October 2026
Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module. When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server.This issue affects Apache HTTP Server: from
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-103921 HIGH 7.4
- CVE-2026-101888 HIGH 7.2
- CVE-2026-101889 MEDIUM 6.5
- CVE-2026-101890 MEDIUM 5.4
- CVE-2026-94620
- CVE-2026-46729 HIGH 7.5
- CVE-2026-42356 LOW 3.7
- CVE-2026-42528 MEDIUM 4.3
- CVE-2026-103690 MEDIUM 6.3
- CVE-2026-97284 HIGH 8.8