Vulnerability record · CVE-2019-10092 · published 26 September 2019
CVE-2019-10092: Apache HTTP Server mod_proxy error page limited XSS
Apache · Http Server
Apache HTTP Server 2.4.0 through 2.4.39 renders a mod_proxy error page whose link can be malformed to point at an attacker-chosen page, a limited cross-site scripting issue (CWE-79). It only triggers when proxying is enabled and misconfigured such that the Proxy Error page is displayed, so exposure is narrow but real for reverse-proxy deployments.
Description
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS 6.1 medium and exploitation requires a misconfigured proxy plus user interaction, but the very high EPSS and public exploit reference raise the practical urgency.
What it is
Apache HTTP Server 2.4.0 through 2.4.39 renders a mod_proxy error page whose link can be malformed to point at an attacker-chosen page, a limited cross-site scripting issue (CWE-79). It only triggers when proxying is enabled and misconfigured such that the Proxy Error page is displayed, so exposure is narrow but real for reverse-proxy deployments.
Impact
An attacker can redirect a victim's browser from the error page to a page of the attacker's choosing, enabling script execution in the context of the affected site and possible credential or session theft. The CVSS scope change (S:C) reflects that the injected content can affect resources beyond the vulnerable component.
Attack surface
Reached over the network via HTTP requests that cause the mod_proxy error page to render; no authentication is required (PR:N) but the victim must interact with the malformed link (UI:R). The server must have proxying enabled and misconfigured so the Proxy Error page is shown.
Exploitation
Not listed in CISA KEV and no ransomware usage documented, but a public exploit reference exists (DrunkenShells disclosure) and EPSS is very high at 0.81466 (99.6th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Upgrade Apache HTTP Server to a release after 2.4.39 that contains the fix, then restart httpd.
- Correct proxy configuration so the Proxy Error page is not exposed to untrusted clients.
- Apply vendor errata for packaged builds (Red Hat RHSA-2019:4126, Debian, Fedora, openSUSE, Ubuntu) rather than building from source where possible.
- Add a Content-Security-Policy and output encoding on error pages to reduce impact of any residual injection.
- Restrict or monitor external access to proxy error responses from untrusted networks.
Detection
- Inspect web and proxy logs for requests that trigger Proxy Error page responses, especially with unusual query strings or path parameters.
- Search HTTP response bodies or cached error pages for injected links or script content on mod_proxy error pages.
- Monitor for outbound redirects or referrer chains originating from proxy error pages to unexpected external domains.
- Track httpd versions in asset inventory and alert on hosts still running 2.4.0-2.4.39 with proxying enabled.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-10092 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-10092), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.