<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Apache — PoC Archive</title><link>https://poc.intelseclab.com/tags/apache/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/apache/index.xml" rel="self" type="application/rss+xml"/><item><title>Apache Traffic Server Internal @Header Metadata Spoofing (CVE-2026-33267)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-33267-apache-trafficserver-header-spoof/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-33267-apache-trafficserver-header-spoof/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-33267 / GHSA-jrh6-9hgv-mqm7. Status: Patched (9.2.15 / 10.1.4). Affects: Apache Traffic Server. Tags: apache, traffic-server, ats, header-injection, metadata-spoof, cache-poisoning, acl-bypass, plugin, CVE-2026-33267.</description><category>web</category><category>Critical</category><category>apache</category><category>traffic-server</category><category>ats</category><category>header-injection</category><category>metadata-spoof</category><category>cache-poisoning</category><category>acl-bypass</category><category>plugin</category><category>CVE-2026-33267</category></item><item><title>Apache mod_ssl TLS 1.3 Session Resumption Client Certificate Bypass (CVE-2025-23048)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-23048-apache-tls13-session-resumption-client-cert-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-23048-apache-tls13-session-resumption-client-cert-bypass/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2025-23048. Status: PoC. Affects: Apache HTTP Server (mod_ssl). Tags: apache, mod_ssl, httpd, tls1.3, session-resumption, client-certificate, authentication-bypass, cwe-295, openssl.</description><category>web</category><category>Critical</category><category>apache</category><category>mod_ssl</category><category>httpd</category><category>tls1.3</category><category>session-resumption</category><category>client-certificate</category><category>authentication-bypass</category><category>cwe-295</category><category>openssl</category></item><item><title>Apache HTTP Server mod_auth_digest Timing Attack — CVE-2026-33006</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33006-apache-mod-auth-digest-timing/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33006-apache-mod-auth-digest-timing/</guid><description>Medium severity (CVSS 4.8) — web · CVE-2026-33006. Status: PoC. Affects: Apache HTTP Server (mod_auth_digest module). Tags: apache, mod_auth_digest, timing-attack, authentication-bypass, digest-auth, http, side-channel.</description><category>web</category><category>Medium</category><category>apache</category><category>mod_auth_digest</category><category>timing-attack</category><category>authentication-bypass</category><category>digest-auth</category><category>http</category><category>side-channel</category></item><item><title>Apache HTTP Server HTTP/2 HPACK Cookie-Merging Memory Bomb (CVE-2026-49975)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-49975-apache-http2-cookie-bomb-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-49975-apache-http2-cookie-bomb-dos/</guid><description>High severity — network · CVE-2026-49975. Status: PoC. Affects: Apache HTTP Server (mod_http2). Tags: apache, httpd, http2, hpack, mod_http2, cookie-header, memory-exhaustion, denial-of-service, flow-control.</description><category>network</category><category>High</category><category>apache</category><category>httpd</category><category>http2</category><category>hpack</category><category>mod_http2</category><category>cookie-header</category><category>memory-exhaustion</category><category>denial-of-service</category><category>flow-control</category></item><item><title>Apache httpd mod_http2 Double-Free Pre-Auth RCE - CVE-2026-23918</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_apache-httpd-mod-http2-double-free/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_apache-httpd-mod-http2-double-free/</guid><description>Critical severity — web · CVE-2026-23918. Status: Weaponized. Affects: Apache HTTP Server (httpd) with mod_http2. Tags: RCE, pre-auth, unauthenticated, double-free, heap-corruption, Apache, httpd, mod_http2, HTTP/2, TLS.</description><category>web</category><category>Critical</category><category>RCE</category><category>pre-auth</category><category>unauthenticated</category><category>double-free</category><category>heap-corruption</category><category>Apache</category><category>httpd</category><category>mod_http2</category><category>HTTP/2</category><category>TLS</category></item></channel></rss>