Vulnerability record · CVE-2002-0840 · published 11 October 2002
CVE-2002-0840: Apache HTTP Server default error page XSS via Host header
Apache · Http Server
Apache 2.0 before 2.0.43 and 1.3.x up to 1.3.26 reflect the Host header into the default error page when UseCanonicalName is Off and wildcard DNS is in use, allowing script injection. The flaw is a cross-site scripting issue distinct from CAN-2002-1157, and it matters because any visitor who reaches an error page can be served attacker-controlled script in the server's origin.
Description
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
AV:N/AC:M/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe flaw is remotely reachable and reflected XSS in a widely deployed web server, and EPSS is near the top of the distribution, though it is not in KEV and requires specific configuration and victim interaction.
What it is
Apache 2.0 before 2.0.43 and 1.3.x up to 1.3.26 reflect the Host header into the default error page when UseCanonicalName is Off and wildcard DNS is in use, allowing script injection. The flaw is a cross-site scripting issue distinct from CAN-2002-1157, and it matters because any visitor who reaches an error page can be served attacker-controlled script in the server's origin.
Impact
An attacker can execute script in the browser of other visitors to the affected site, enabling session theft, credential capture or redirection within the site's trust context.
Attack surface
Reached remotely over HTTP by sending a crafted Host header to a server configured with UseCanonicalName Off and wildcard DNS; no authentication is required, but the victim must load the resulting error page, so some user interaction is implied.
Exploitation
Not listed in CISA KEV and no ransomware use is documented; EPSS is very high (0.95087, 99.859th percentile), and references are vendor advisories and distro errata rather than public exploit tags.
What to do
- Upgrade Apache to 2.0.43 or later, or the fixed 1.3.x release, and apply the linked vendor errata for Oracle, Red Hat, Debian and Mandrake packages.
- Set UseCanonicalName to On where operationally possible to stop the Host header being reflected.
- Disable wildcard DNS for the affected virtual hosts so arbitrary Host values do not resolve to the server.
- Replace or customize default error pages so request headers are not echoed into responses.
- Encode or reject untrusted Host header values at the reverse proxy or web server layer.
Detection
- Search web server access and error logs for Host header values containing script tags, angle brackets or encoded HTML entities.
- Monitor for requests that trigger error responses (4xx/5xx) with unusual Host values from the same source.
- Review error page responses for reflected Host header content using an HTTP proxy or scanner.
- Alert on configuration drift where UseCanonicalName is set to Off on internet-facing Apache instances.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2002-0840 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2002-0840), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.