Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.

Published: 2024-07-01

CVSS: 7.5

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Download CVE-2024-39573 POC (Proof-of-Concept) here:

Tip: Download official Tor Browser at https://www.torproject.org/download/ to access .onion links.

https://connollyfinan.ie/poc-334-cve-2025-49706/

https://connollyfinan.ie/poc-253-cve-2025-62473/

https://connollyfinan.ie/poc-548-cve-2016-2183/

https://connollyfinan.ie/poc-11-cve-2023-26604/

https://connollyfinan.ie/poc-406-cve-2022-0185/