<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:39:26.278538+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:30844</id>
    <title>ALSA-2026:30844 — Moderate: mod_md security update</title>
    <updated>2026-10-03T20:39:26.306833+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: mod_md</p>
<p>This module manages common properties of domains for one or more virtual hosts. Specifically it can use the ACME protocol to automate certificate provisioning. Certificates will be configured for managed domains and their virtual hosts automatically, including at renewal.</p>
<p>Security Fix(es):</p>
<p>* httpd: mod_md: unrestricted OCSP response leads to resource exhaustion (CVE-2026-29168)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:30844"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-06409</id>
    <title>bdu:2026-06409</title>
    <updated>2026-10-03T20:39:26.306896+00:00</updated>
    <content>bdu:2026-06409</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-06409"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-29168</id>
    <title>BELL-CVE-2026-29168</title>
    <updated>2026-10-03T20:39:26.306913+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: apache2, Alpaquita:25: apache2, Alpaquita:stream: apache2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-29168"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-apache-2026-29168</id>
    <title>BIT-apache-2026-29168 — Apache HTTP Server: mod_md unrestricted OCSP response</title>
    <updated>2026-10-03T20:39:26.306934+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: apache</p>
<p>Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response data.</p>
<p>This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.</p>
<p>Users are recommended to upgrade to version 2.4.67, which fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-apache-2026-29168"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0530</id>
    <title>certfr-2026-avi-0530 — De multiples vulnérabilités ont été découvertes dans Apache HTTP Server. Certaines d'entre elles permettent à un attaqu…</title>
    <updated>2026-10-03T20:39:26.306957+00:00</updated>
    <content>certfr-2026-avi-0530</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0530"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2026-21700</id>
    <title>cnvd-2026-21700</title>
    <updated>2026-10-03T20:39:26.306972+00:00</updated>
    <content>cnvd-2026-21700</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2026-21700"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-308603</id>
    <title>EUVD-2026-308603</title>
    <updated>2026-10-03T20:39:26.306983+00:00</updated>
    <content>EUVD-2026-308603</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-308603"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-29168</id>
    <title>fkie_cve-2026-29168</title>
    <updated>2026-10-03T20:39:26.306993+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response data.</p>
<p>This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.</p>
<p>Users are recommended to upgrade to version 2.4.67, which fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-29168"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h688-wmf2-q99q</id>
    <title>GHSA-h688-wmf2-q99q</title>
    <updated>2026-10-03T20:39:26.307016+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response data.</p>
<p>This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.</p>
<p>Users are recommended to upgrade to version 2.4.67, which fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h688-wmf2-q99q"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-29168</id>
    <title>msrc_CVE-2026-29168 — Apache HTTP Server: mod_md unrestricted OCSP response</title>
    <updated>2026-10-03T20:39:26.307032+00:00</updated>
    <content>msrc_CVE-2026-29168</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-29168"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0134</id>
    <title>NCSC-2026-0134 — Kwetsbaarheden verholpen in Apache HTTP Server</title>
    <updated>2026-10-03T20:39:26.307048+00:00</updated>
    <content>NCSC-2026-0134</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0134"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2316</id>
    <title>OESA-2026-2316 — httpd security update</title>
    <updated>2026-10-03T20:39:26.307076+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP3: httpd</p>
<p>Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.

Security Fix(es):</p>
<p>An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.</p>
<p>Users are recommended to upgrade to version 2.4.67, which fixes this issue.(CVE-2026-24072)</p>
<p>Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.
If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.</p>
<p>This issue affects Apache HTTP Server: through 2.4.66.</p>
<p>Users are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-28780)</p>
<p>Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server&amp;apos;s  mod_md via OCSP response data.</p>
<p>This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.</p>
<p>Users are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-29168)</p>
<p>A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs.</p>
<p>The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0.</p>
<p>Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2316"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10785-1</id>
    <title>openSUSE-SU-2026:10785-1 — apache2-2.4.67-1.1 on GA media</title>
    <updated>2026-10-03T20:39:26.307115+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>apache2-2.4.67-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10785-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:27200</id>
    <title>RHSA-2026:27200 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.62 SP4 security update</title>
    <updated>2026-10-03T20:39:26.307137+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>mod_http2: Apache HTTP Server: HTTP/2 DoS by Memory Increase nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow httpd: mod_md: unrestricted OCSP response leads to resource exhaustion httpd: NULL pointer dereference via specially crafted request httpd: mod_authn_socache: NULL pointer dereference can cause a child process crash httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check httpd: mod_proxy_ajp: heap-based buffer over-read and memory disclosure in ajp_parse_data() httpd: httpd: HTTP/2 Remote Denial of Service via compression bomb and Slowloris-style attack</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:27200"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:30844</id>
    <title>RLSA-2026:30844 — Moderate: mod_md security update</title>
    <updated>2026-10-03T20:39:26.307169+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: mod_md</p>
<p>This module manages common properties of domains for one or more virtual hosts. Specifically it can use the ACME protocol to automate certificate provisioning.  Certificates will be configured for managed domains and their virtual hosts automatically, including at renewal.</p>
<p>Security Fix(es):</p>
<p>* httpd: mod_md: unrestricted OCSP response leads to resource exhaustion (CVE-2026-29168)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:30844"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:2103-1</id>
    <title>SUSE-SU-2026:2103-1 — Security update for apache2</title>
    <updated>2026-10-03T20:39:26.307191+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for apache2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:2103-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-29168</id>
    <title>UBUNTU-CVE-2026-29168</title>
    <updated>2026-10-03T20:39:26.307209+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: apache2, Ubuntu:24.04:LTS: apache2, Ubuntu:25.10: apache2, Ubuntu:26.04:LTS: apache2</p>
<p>Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-29168"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1354</id>
    <title>WID-SEC-W-2026-1354 — Apache HTTP Server: Mehrere Schwachstellen</title>
    <updated>2026-10-03T20:39:26.307252+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Apache HTTP Server ausnutzen, um erweiterte Privilegien zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1354"/>
  </entry>
</feed>
