Vulnerability record · CVE-2020-1927 · published 2 April 2020
CVE-2020-1927: Apache HTTP Server mod_rewrite encoded newline open redirect
Apache · Http Server
Apache HTTP Server 2.4.0 through 2.4.41 mishandles redirects configured with mod_rewrite that were meant to be self-referential; encoded newlines can cause the redirect to point to an unexpected URL within the request URL. This is an open redirect (CWE-601) that can be abused to send users to attacker-chosen destinations while appearing to originate from a trusted host.
Description
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it medium (6.1) and it requires user interaction, but the high EPSS score and broad deployment of Apache HTTP Server warrant prompt patching.
What it is
Apache HTTP Server 2.4.0 through 2.4.41 mishandles redirects configured with mod_rewrite that were meant to be self-referential; encoded newlines can cause the redirect to point to an unexpected URL within the request URL. This is an open redirect (CWE-601) that can be abused to send users to attacker-chosen destinations while appearing to originate from a trusted host.
Impact
An attacker can redirect a victim to an unintended URL, enabling phishing, credential harvesting or malware delivery under the guise of the trusted site. The CVSS vector shows only low confidentiality and integrity impact, with no availability impact.
Attack surface
Reachable over the network (AV:N) with no privileges required (PR:N), but exploitation requires user interaction (UI:R) because a victim must follow a crafted link. It applies only where mod_rewrite self-referential redirects are configured.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is high at 0.567 (99th percentile), indicating elevated likelihood of attempted exploitation. Reference tags are advisory and patch notices only, with no public exploit tag.
What to do
- Upgrade Apache HTTP Server to a version later than 2.4.41 that contains the fix, or apply the vendor patch referenced in the Apache security advisory.
- Update packaged httpd in Debian, Ubuntu, Fedora, openSUSE and other distributions using the linked vendor advisories.
- Review mod_rewrite rules that generate self-referential redirects and avoid patterns that can be influenced by encoded newline characters in the request URL.
- Where feasible, validate or normalize redirect targets and avoid reflecting request-derived values into Location headers.
- Patch dependent products that bundle httpd, such as NetApp, Brocade and Oracle components listed in the record.
Detection
- Monitor web server access logs for requests containing encoded newline sequences (%0a, %0d) in URLs that trigger redirects.
- Alert on outbound redirects (3xx Location headers) pointing to hosts outside the expected domain set.
- Correlate spikes in redirect responses from mod_rewrite-enabled paths with unusual referrer or user-agent patterns.
- Review mod_rewrite configuration changes and audit rules that build redirect targets from request data.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
14 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-1927 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-1927), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.