<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T03:28:49.584976+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:14625</id>
    <title>ALSA-2025:14625 — Moderate: mod_http2 security update</title>
    <updated>2026-10-04T03:28:49.628994+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: mod_http2</p>
<p>The mod_h2 Apache httpd module implements the HTTP2 protocol (h2+h2c) on top of libnghttp2 for httpd 2.4 servers.</p>
<p>Security Fix(es):</p>
<p>* httpd: mod_proxy_http2: untrusted input from a client causes an assertion to fail in the Apache mod_proxy_http2 module (CVE-2025-49630)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:14625"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-08695</id>
    <title>bdu:2025-08695</title>
    <updated>2026-10-04T03:28:49.629063+00:00</updated>
    <content>bdu:2025-08695</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-08695"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-49630</id>
    <title>BELL-CVE-2025-49630</title>
    <updated>2026-10-04T03:28:49.629081+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: apache2, Alpaquita:25: apache2, Alpaquita:stream: apache2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-49630"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-apache-2025-49630</id>
    <title>BIT-apache-2025-49630 — Apache HTTP Server: mod_proxy_http2 denial of service</title>
    <updated>2026-10-04T03:28:49.629104+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: apache</p>
<p>In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2.</p>
<p>Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-apache-2025-49630"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0586</id>
    <title>certfr-2025-avi-0586 — De multiples vulnérabilités ont été découvertes dans Apache HTTP Server. Certaines d'entre elles permettent à un attaqu…</title>
    <updated>2026-10-04T03:28:49.629128+00:00</updated>
    <content>certfr-2025-avi-0586</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0586"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2025-16603</id>
    <title>cnvd-2025-16603</title>
    <updated>2026-10-04T03:28:49.629144+00:00</updated>
    <content>cnvd-2025-16603</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2025-16603"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-259970</id>
    <title>EUVD-2026-259970</title>
    <updated>2026-10-04T03:28:49.629155+00:00</updated>
    <content>EUVD-2026-259970</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-259970"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-49630</id>
    <title>fkie_cve-2025-49630</title>
    <updated>2026-10-04T03:28:49.629165+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2.</p>
<p>Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-49630"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-72h2-3r97-f454</id>
    <title>GHSA-72h2-3r97-f454</title>
    <updated>2026-10-04T03:28:49.629188+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2.</p>
<p>Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-72h2-3r97-f454"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2026-003910</id>
    <title>jvndb-2026-003910</title>
    <updated>2026-10-04T03:28:49.629204+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple vulnerabilities have been found in Cosminexus HTTP Server.

CVE-2025-49630, CVE-2025-53020

These vulnerabilities does not apply if HTTP/2 protocol is disabled.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2026-003910"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-49630</id>
    <title>msrc_CVE-2025-49630 — Apache HTTP Server: mod_proxy_http2 denial of service</title>
    <updated>2026-10-04T03:28:49.629221+00:00</updated>
    <content>msrc_CVE-2025-49630</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-49630"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2076</id>
    <title>OESA-2025-2076 — mod_http2 security update</title>
    <updated>2026-10-04T03:28:49.629237+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: mod_http2, openEuler:22.03-LTS-SP4: mod_http2, openEuler:24.03-LTS: mod_http2, openEuler:24.03-LTS-SP1: mod_http2, openEuler:24.03-LTS-SP2: mod_http2, openEuler:20.03-LTS-SP4: mod_http2</p>
<p>The mod_h2 Apache httpd module implements the HTTP2 protocol (h2+h2c) on top of libnghttp2 for httpd 2.4 servers.

Security Fix(es):</p>
<p>A vulnerability classified as problematic has been found in Apache HTTP Server up to 2.4.63 (Web Server).CWE is classifying the issue as CWE-617. The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.This is going to have an impact on availability.Upgrading to version 2.4.64 eliminates this vulnerability.The vulnerability is also documented in the vulnerability database at EUVD (EUVD-2025-21017).(CVE-2025-49630)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2076"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15360-1</id>
    <title>openSUSE-SU-2025:15360-1 — apache2-2.4.64-1.1 on GA media</title>
    <updated>2026-10-04T03:28:49.629275+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>apache2-2.4.64-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15360-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:13680</id>
    <title>RHSA-2025:13680 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.62 SP1 security update</title>
    <updated>2026-10-04T03:28:49.629296+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>httpd: insufficient escaping of user-supplied data in mod_ssl httpd: mod_ssl: access control bypass by trusted clients is possible using TLS 1.3 session resumption modsecurity: ModSecurity Has Possible DoS Vulnerability httpd: mod_proxy_http2: untrusted input from a client causes an assertion to fail in the Apache mod_proxy_http2 module httpd: HTTP Session Hijack via a TLS upgrade</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:13680"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:02565-1</id>
    <title>SUSE-SU-2025:02565-1 — Security update for apache2</title>
    <updated>2026-10-04T03:28:49.629319+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for apache2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:02565-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-49630</id>
    <title>UBUNTU-CVE-2025-49630</title>
    <updated>2026-10-04T03:28:49.629336+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: apache2, Ubuntu:Pro:20.04:LTS: apache2, Ubuntu:22.04:LTS: apache2, Ubuntu:24.04:LTS: apache2</p>
<p>In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-49630"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1529</id>
    <title>WID-SEC-W-2025-1529 — Apache HTTP Server: Mehrere Schwachstellen</title>
    <updated>2026-10-04T03:28:49.629360+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Apache HTTP Server ausnutzen, um einen Denial of Service Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, und um Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1529"/>
  </entry>
</feed>
