{
  "from_raw": "Eric Covener <covener@apache.org>",
  "from": "Eric Covener <co...@apache.org>",
  "gravatar": "ee9bd44fca004cd144fce0d972679406",
  "to": "an...@apache.org,\n de...@httpd.apache.org",
  "subject": "CVE-2026-47360: Apache HTTP Server: mod_session: Session cookie not removed during internal redirect",
  "message-id": "<a3c1890e-6248-0962-e0f3-1850645c912b@apache.org>",
  "mid": "ctxwvy1jn00xjv0qkdtzr8nzj0mpld8t",
  "permalinks": [
    "ctxwvy1jn00xjv0qkdtzr8nzj0mpld8t",
    "ra53f748243289143c81f7ebe8ef1960ed692d2f7a802147713f221f0@<dev.httpd.apache.org>"
  ],
  "dbid": "21369121524e5ef677f4a097d75e7b5c5376dd25660dd7c1fad4370561e9f030",
  "cc": "",
  "epoch": 1790877801,
  "list": "<dev.httpd.apache.org>",
  "list_raw": "<dev.httpd.apache.org>",
  "date": "2026/10/01 18:03:21",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: low \n\nAffected versions:\n\n- Apache HTTP Server 2.4.0 through 2.4.68\n\nDescription:\n\nExposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.\n\n\n\n\u00a0  \nWhen SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server.\n\n\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.\n\nCredit:\n\nlokerxx (finder)\n\nReferences:\n\nhttps://httpd.apache.org/security/vulnerabilities_24.html\nhttps://httpd.apache.org/\nhttps://www.cve.org/CVERecord?id=CVE-2026-47360\n\nTimeline:\n\n2026-05-15: reported\n2026-10-01: fixed in 2.4.x by r1938656\n2026-10-01: 2.4.69 released\n\n",
  "body_short": "Severity: low \n\nAffected versions:\n\n- Apache HTTP Server 2.4.0 through 2.4.68\n\nDescription:\n\nExposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session",
  "html_source_only": false,
  "attachments": [],
  "forum": "dev@httpd.apache.org",
  "size": 3867,
  "id": "ctxwvy1jn00xjv0qkdtzr8nzj0mpld8t"
}