<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:44:25.709460+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-11947</id>
    <title>bdu:2026-11947</title>
    <updated>2026-10-02T18:44:25.897421+00:00</updated>
    <content>bdu:2026-11947</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-11947"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-29170</id>
    <title>BELL-CVE-2026-29170</title>
    <updated>2026-10-02T18:44:25.897462+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: apache2, Alpaquita:25: apache2, Alpaquita:stream: apache2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-29170"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-apache-2026-29170</id>
    <title>BIT-apache-2026-29170 — Apache HTTP Server: mod_proxy_ftp XSS</title>
    <updated>2026-10-02T18:44:25.897493+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: apache</p>
<p>A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration.</p>
<p>Users are recommended to upgrade to version 2.4.68, which fixes this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-apache-2026-29170"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0710</id>
    <title>certfr-2026-avi-0710 — De multiples vulnérabilités ont été découvertes dans Apache HTTP Server. Certaines d'entre elles permettent à un attaqu…</title>
    <updated>2026-10-02T18:44:25.897521+00:00</updated>
    <content>certfr-2026-avi-0710</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0710"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-325672</id>
    <title>EUVD-2026-325672</title>
    <updated>2026-10-02T18:44:25.897537+00:00</updated>
    <content>EUVD-2026-325672</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-325672"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-29170</id>
    <title>fkie_cve-2026-29170</title>
    <updated>2026-10-02T18:44:25.897548+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration.</p>
<p>Users are recommended to upgrade to version 2.4.68, which fixes this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-29170"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9rm4-vpqg-mfpc</id>
    <title>GHSA-9rm4-vpqg-mfpc</title>
    <updated>2026-10-02T18:44:25.897571+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration.</p>
<p>Users are recommended to upgrade to version 2.4.68, which fixes this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9rm4-vpqg-mfpc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-29170</id>
    <title>msrc_CVE-2026-29170 — Apache HTTP Server: mod_proxy_ftp XSS</title>
    <updated>2026-10-02T18:44:25.897587+00:00</updated>
    <content>msrc_CVE-2026-29170</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-29170"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2744</id>
    <title>OESA-2026-2744 — httpd security update</title>
    <updated>2026-10-02T18:44:25.897603+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: httpd</p>
<p>Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.

Security Fix(es):</p>
<p>Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration</p>
<p>This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.</p>
<p>Users are recommended to upgrade to version 2.4.68, which fixes the issue.(CVE-2026-29167)</p>
<p>A cross-site scripting vulnerability exists in mod_proxy_ftp&amp;apos;s HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration.</p>
<p>Users are recommended to upgrade to version 2.4.68, which fixes this issue.(CVE-2026-29170)</p>
<p>A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.(CVE-2026-34355)</p>
<p>Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie*</p>
<p>This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.</p>
<p>Users are recommended to upgrade to version 2.4.68, which fixes the issue.(CVE-2026-34356)</p>
<p>A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes.</p>
<p>Users are recommended to upgrade to version 2.4.68, which fixes this issue.(CVE-2026-42535)</p>
<p>Heap-based Buffer Overflow vulnerability…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2744"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21235-1</id>
    <title>openSUSE-SU-2026:21235-1 — Security update for apache2</title>
    <updated>2026-10-02T18:44:25.897646+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for apache2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21235-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:25042</id>
    <title>RHSA-2026:25042 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T18:44:25.897679+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>httpd: Apache HTTP Server: Arbitrary code execution or denial of service via use-after-free in mod_ldap per-directory configuration httpd: Apache HTTP Server: Cross-site scripting in mod_proxy_ftp via HTML directory list generation httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server httpd: Apache HTTP Server: Denial of Service via crafted regular expressions httpd: mod_http2: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service. httpd: httpd: HTTP/2 Remote Denial of Service via compression bomb and Slowloris-style attack</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:25042"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22564-1</id>
    <title>SUSE-SU-2026:22564-1 — Security update for apache2</title>
    <updated>2026-10-02T18:44:25.897751+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for apache2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22564-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-29170</id>
    <title>UBUNTU-CVE-2026-29170</title>
    <updated>2026-10-02T18:44:25.897771+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: apache2, Ubuntu:Pro:16.04:LTS: apache2, Ubuntu:Pro:18.04:LTS: apache2, Ubuntu:Pro:20.04:LTS: apache2, Ubuntu:22.04:LTS: apache2, Ubuntu:24.04:LTS: apache2, Ubuntu:25.10: apache2, Ubuntu:26.04:LTS: apache2</p>
<p>A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to version 2.4.68, which fixes this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-29170"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1824</id>
    <title>WID-SEC-W-2026-1824 — Apache HTTP Server: Mehrere Schwachstellen</title>
    <updated>2026-10-02T18:44:25.897800+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Apache HTTP Server ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu verändern und offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder andere nicht näher definierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1824"/>
  </entry>
</feed>
