<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:55:57.091683+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:41906</id>
    <title>ALSA-2026:41906 — Important: httpd security, bug fix, and enhancement update</title>
    <updated>2026-10-03T04:55:57.533250+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: httpd, AlmaLinux:9: httpd-core, AlmaLinux:9: httpd-devel, AlmaLinux:9: httpd-filesystem, AlmaLinux:9: httpd-manual, AlmaLinux:9: httpd-tools, AlmaLinux:9: mod_ldap, AlmaLinux:9: mod_lua, AlmaLinux:9: mod_proxy_html, AlmaLinux:9: mod_session and 1 more</p>
<p>The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.</p>
<p>Security Fix(es):</p>
<p>* httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516)
  * Apache HTTP Server: mod_rewrite: Apache HTTP Server: Privilege Escalation via .htaccess file manipulation (CVE-2026-24072)
  * httpd: mod_auth_digest: timing attack allows a bypass of digest authentication (CVE-2026-33006)
  * httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169)
  * httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356)
  * httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
  * httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631)
  * httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186)
  * httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue (CVE-2026-42535)
  * httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536)
  * httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355)
  * httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime (CVE-2026-43951)
  * httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges (CVE-2026-44119)</p>
<p>Bug Fix(es) and Enhancement(s):…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:41906"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-06354</id>
    <title>bdu:2026-06354</title>
    <updated>2026-10-03T04:55:57.533347+00:00</updated>
    <content>bdu:2026-06354</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-06354"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-24072</id>
    <title>BELL-CVE-2026-24072</title>
    <updated>2026-10-03T04:55:57.533365+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: apache2, Alpaquita:25: apache2, Alpaquita:stream: apache2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-24072"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-apache-2026-24072</id>
    <title>BIT-apache-2026-24072 — Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr</title>
    <updated>2026-10-03T04:55:57.533388+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: apache</p>
<p>An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.</p>
<p>Users are recommended to upgrade to version 2.4.67, which fixes this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-apache-2026-24072"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0530</id>
    <title>certfr-2026-avi-0530 — De multiples vulnérabilités ont été découvertes dans Apache HTTP Server. Certaines d'entre elles permettent à un attaqu…</title>
    <updated>2026-10-03T04:55:57.533409+00:00</updated>
    <content>certfr-2026-avi-0530</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0530"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2026-21691</id>
    <title>cnvd-2026-21691</title>
    <updated>2026-10-03T04:55:57.533425+00:00</updated>
    <content>cnvd-2026-21691</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2026-21691"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-308509</id>
    <title>EUVD-2026-308509</title>
    <updated>2026-10-03T04:55:57.533436+00:00</updated>
    <content>EUVD-2026-308509</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-308509"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-24072</id>
    <title>fkie_cve-2026-24072</title>
    <updated>2026-10-03T04:55:57.533446+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.</p>
<p>Users are recommended to upgrade to version 2.4.67, which fixes this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-24072"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9pw3-5ggm-c92r</id>
    <title>GHSA-9pw3-5ggm-c92r</title>
    <updated>2026-10-03T04:55:57.533468+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.</p>
<p>Users are recommended to upgrade to version 2.4.67, which fixes this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9pw3-5ggm-c92r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-24072</id>
    <title>msrc_CVE-2026-24072 — Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr</title>
    <updated>2026-10-03T04:55:57.533482+00:00</updated>
    <content>msrc_CVE-2026-24072</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-24072"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0134</id>
    <title>NCSC-2026-0134 — Kwetsbaarheden verholpen in Apache HTTP Server</title>
    <updated>2026-10-03T04:55:57.533497+00:00</updated>
    <content>NCSC-2026-0134</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0134"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2316</id>
    <title>OESA-2026-2316 — httpd security update</title>
    <updated>2026-10-03T04:55:57.533526+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP3: httpd</p>
<p>Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.

Security Fix(es):</p>
<p>An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.</p>
<p>Users are recommended to upgrade to version 2.4.67, which fixes this issue.(CVE-2026-24072)</p>
<p>Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.
If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.</p>
<p>This issue affects Apache HTTP Server: through 2.4.66.</p>
<p>Users are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-28780)</p>
<p>Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server&amp;apos;s  mod_md via OCSP response data.</p>
<p>This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.</p>
<p>Users are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-29168)</p>
<p>A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs.</p>
<p>The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0.</p>
<p>Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2316"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10785-1</id>
    <title>openSUSE-SU-2026:10785-1 — apache2-2.4.67-1.1 on GA media</title>
    <updated>2026-10-03T04:55:57.533567+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>apache2-2.4.67-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10785-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:13938</id>
    <title>RHSA-2026:13938 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-03T04:55:57.533589+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache HTTP Server: Apache HTTP Server: Remote Code Execution via Double Free in HTTP/2 Protocol Apache HTTP Server: mod_rewrite: Apache HTTP Server: Privilege Escalation via .htaccess file manipulation httpd: mod_authn_socache: NULL pointer dereference can cause a child process crash httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check httpd: mod_proxy_ajp: heap-based buffer over-read and memory disclosure in ajp_parse_data()</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:13938"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:34109</id>
    <title>RLSA-2026:34109 — Important: httpd security, bug fix, and enhancement update</title>
    <updated>2026-10-03T04:55:57.533614+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: httpd</p>
<p>The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.</p>
<p>Security Fix(es):</p>
<p>* httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516)</p>
<p>* httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169)</p>
<p>* httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356)</p>
<p>* httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185)</p>
<p>* httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631)</p>
<p>* httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536)</p>
<p>* httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* address Moderate severity issues from httpd 2.4.68 [rhel-10.2.z] (JIRA:Rocky Linux-184518)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:34109"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:2103-1</id>
    <title>SUSE-SU-2026:2103-1 — Security update for apache2</title>
    <updated>2026-10-03T04:55:57.533645+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for apache2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:2103-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-24072</id>
    <title>UBUNTU-CVE-2026-24072</title>
    <updated>2026-10-03T04:55:57.533664+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: apache2, Ubuntu:Pro:16.04:LTS: apache2, Ubuntu:Pro:18.04:LTS: apache2, Ubuntu:Pro:20.04:LTS: apache2, Ubuntu:22.04:LTS: apache2, Ubuntu:24.04:LTS: apache2, Ubuntu:25.10: apache2, Ubuntu:26.04:LTS: apache2</p>
<p>An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which fixes this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-24072"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1354</id>
    <title>WID-SEC-W-2026-1354 — Apache HTTP Server: Mehrere Schwachstellen</title>
    <updated>2026-10-03T04:55:57.533692+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Apache HTTP Server ausnutzen, um erweiterte Privilegien zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1354"/>
  </entry>
</feed>
