VYPR
High severity7.5NVD Advisory· Published Oct 1, 2026· Updated Oct 1, 2026

CVE-2026-47360

CVE-2026-47360

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.

When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server.

This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.