CVE-2024-38475

Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected.  Some unsafe RewiteRules will be broken by this change and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained.


We have discovered 1,328,741 live websites that are affected by CVE-2024-38475.

Run a Free Instant Scan




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains1,328,741 live websites (48% of Apache install base)
Vulnerable Versions
  • from 2.4 through 2.4.59
Vulnerable Versions Count51 versions ( 43% of all versions)


Common Weakness Enumeration

CWE-116 Improper Encoding or Escaping of Output



Details

  • Published - Jul 1, 2024
  • Updated - Nov 3, 2025

Credits

  • Orange Tsai (@orange_8361) from DEVCORE (finder)

Website Distribution by Country

Number of websites using CVE-2024-38475
United States399,606 websites



Germany151,624 websites
France79,441 websites
Netherlands62,741 websites
Japan48,904 websites
Russia48,300 websites
Italy46,493 websites
Singapore36,529 websites
GB36,117 websites
Czech Republic34,920 websites

Website Distribution by TLD

Number of websites using CVE-2024-38475
.com484,575 websites
.de90,241 websites
.org64,567 websites
.net52,720 websites
.nl47,215 websites
.ru42,753 websites
.it41,347 websites
.cz29,091 websites
.fr26,275 websites
.pl25,745 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-38475

Top websites that are affected by CVE-2024-38475. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com Singapore***
*************.***.****.****.************.net United States***
*********.net United States***
***.****.us United States*,***
***.*********.com Singapore*,***
*****.*******.com Singapore*,***
******.net Sweden*,***
******************.com United States*,***
****.*********.net GB*,***
****.com United States*,***
See full domain list

FAQ

CVE-2024-38475 is Improper Encoding or Escaping of Output in Apache
A total of 1,328,741 websites have been identified as vulnerable to CVE-2024-38475, based on global website indexing conducted by WebTechSurvey.
The Apache is affected by the CVE-2024-38475 vulnerability.
Apache versions up to and including 2.4.59 are vulnerable to CVE-2024-38475.