← Vulnerability feed

Vulnerability record · CVE-2019-10092 · published 26 September 2019

CVE-2019-10092: Apache HTTP Server mod_proxy error page limited XSS

Apache · Http Server

Apache HTTP Server 2.4.0 through 2.4.39 renders a mod_proxy error page whose link can be malformed to point at an attacker-chosen page, a limited cross-site scripting issue (CWE-79). It only triggers when proxying is enabled and misconfigured such that the Proxy Error page is displayed, so exposure is narrow but real for reverse-proxy deployments.

6.1 CVSS 3.1 Medium EPSS 81% · top 0.4% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
81%EPSS exploitation probability, 30 days
NoNot in CISA KEV
10Affected product versions listed by NVD
68References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

medium priorityCVSS 6.1 medium and exploitation requires a misconfigured proxy plus user interaction, but the very high EPSS and public exploit reference raise the practical urgency.

What it is

Apache HTTP Server 2.4.0 through 2.4.39 renders a mod_proxy error page whose link can be malformed to point at an attacker-chosen page, a limited cross-site scripting issue (CWE-79). It only triggers when proxying is enabled and misconfigured such that the Proxy Error page is displayed, so exposure is narrow but real for reverse-proxy deployments.

Impact

An attacker can redirect a victim's browser from the error page to a page of the attacker's choosing, enabling script execution in the context of the affected site and possible credential or session theft. The CVSS scope change (S:C) reflects that the injected content can affect resources beyond the vulnerable component.

Attack surface

Reached over the network via HTTP requests that cause the mod_proxy error page to render; no authentication is required (PR:N) but the victim must interact with the malformed link (UI:R). The server must have proxying enabled and misconfigured so the Proxy Error page is shown.

Exploitation

Not listed in CISA KEV and no ransomware usage documented, but a public exploit reference exists (DrunkenShells disclosure) and EPSS is very high at 0.81466 (99.6th percentile), indicating elevated likelihood of attempted exploitation.

What to do

  • Upgrade Apache HTTP Server to a release after 2.4.39 that contains the fix, then restart httpd.
  • Correct proxy configuration so the Proxy Error page is not exposed to untrusted clients.
  • Apply vendor errata for packaged builds (Red Hat RHSA-2019:4126, Debian, Fedora, openSUSE, Ubuntu) rather than building from source where possible.
  • Add a Content-Security-Policy and output encoding on error pages to reduce impact of any residual injection.
  • Restrict or monitor external access to proxy error responses from untrusted networks.

Detection

  • Inspect web and proxy logs for requests that trigger Proxy Error page responses, especially with unusual query strings or path parameters.
  • Search HTTP response bodies or cached error pages for injected links or script content on mod_proxy error pages.
  • Monitor for outbound redirects or referrer chains originating from proxy error pages to unexpected external domains.
  • Track httpd versions in asset inventory and alert on hosts still running 2.4.0-2.4.39 with proxying enabled.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00004.html Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2019/08/15/4 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2020/08/08/1 Mailing List
http://www.openwall.com/lists/oss-security/2020/08/08/9 Mailing List
https://access.redhat.com/errata/RHSA-2019:4126 Third Party Advisory
https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-10092-Limited%20Cross-Site%20Scripting%20in%20mod_prox ExploitThird Party Advisory
https://httpd.apache.org/security/vulnerabilities_24.html Vendor Advisory
https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%
https://lists.apache.org/thread.html/73768e31e0fcae03e12f5aa87da1cb26dece39327f3c32060baa3e94%40%3Cannounce.httpd.apache
https://lists.apache.org/thread.html/r03ee478b3dda3e381fd6189366fa7af97c980d2f602846eef935277d%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r0a83b112cd9701ef8a2061c8ed557f3dc9bb774d4da69fbb91bbc3c4%40%3Cusers.httpd.apache.o
https://lists.apache.org/thread.html/r3c5c3104813c1c5508b55564b66546933079250a46ce50eee90b2e36%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/rd2fb621142e7fa187cfe12d7137bf66e7234abcbbcd800074c84a538%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org
https://lists.debian.org/debian-lts-announce/2019/08/msg00034.html Mailing ListThird Party Advisory
https://lists.debian.org/debian-lts-announce/2019/09/msg00034.html Mailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7RVHJHTU4JN3ULCQ44F2G6L
https://seclists.org/bugtraq/2019/Aug/47 Mailing ListThird Party Advisory
https://seclists.org/bugtraq/2019/Oct/24 Mailing ListThird Party Advisory
https://security.gentoo.org/glsa/201909-04 Third Party Advisory
https://security.netapp.com/advisory/ntap-20190905-0003/ Third Party Advisory
https://support.f5.com/csp/article/K30442259 Third Party Advisory
https://usn.ubuntu.com/4113-1/ PatchThird Party Advisory
https://www.debian.org/security/2019/dsa-4509 Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2020.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html PatchThird Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html PatchThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00004.html Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2019/08/15/4 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2020/08/08/1 Mailing List
http://www.openwall.com/lists/oss-security/2020/08/08/9 Mailing List
https://access.redhat.com/errata/RHSA-2019:4126 Third Party Advisory
https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-10092-Limited%20Cross-Site%20Scripting%20in%20mod_prox ExploitThird Party Advisory

Track CVE-2019-10092 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2024-4577PHP-CGI on Windows argument injection leads to remote code executionPHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windo…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2019-10092), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.