<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:54:52 +0000</lastBuildDate>
    <item>
      <title>bdu:2019-00886</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-00886</link>
      <description>bdu:2019-00886</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-00886</guid>
    </item>
    <item>
      <title>cnvd-2018-22373</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-22373</link>
      <description>cnvd-2018-22373</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-22373</guid>
    </item>
    <item>
      <title>EUVD-2026-65424</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-65424</link>
      <description>EUVD-2026-65424</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-65424</guid>
    </item>
    <item>
      <title>fkie_cve-2018-11759</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-11759</link>
      <description>&lt;p&gt;The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. It was also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. While there is some overlap between this issue and CVE-2018-1323, they are not identical.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. It was also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. While there is some overlap between this issue and CVE-2018-1323, they are not identical.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-11759</guid>
    </item>
    <item>
      <title>GHSA-5q2c-33mg-8m75</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5q2c-33mg-8m75</link>
      <description>&lt;p&gt;The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. It was also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. While there is some overlap between this issue and CVE-2018-1323, they are not identical.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. It was also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. While there is some overlap between this issue and CVE-2018-1323, they are not identical.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5q2c-33mg-8m75</guid>
    </item>
    <item>
      <title>gsd-2018-11759</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-11759</link>
      <description>gsd-2018-11759</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-11759</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10625-1 — apache2-mod_jk-1.2.48-2.9 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10625-1</link>
      <description>&lt;p&gt;apache2-mod_jk-1.2.48-2.9 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apache2-mod_jk-1.2.48-2.9 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10625-1</guid>
    </item>
    <item>
      <title>RHSA-2019:0366 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.29 SP1 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2019:0366</link>
      <description>&lt;p&gt;libdb: Reads DB_CONFIG from the current working directory httpd: Out of bounds write in mod_authnz_ldap when using too small Accept-Language values httpd: &amp;lt;FilesMatch&amp;gt; bypass with a trailing newline in the file name openssl: Handling of crafted recursive ASN.1 structures can cause a stack overflow and resulting denial of service httpd: Improper handling of headers in mod_session can allow a remote user to modify session data for CGI applications httpd: Out of bounds access after failure in reading the HTTP request httpd: Use-after-free on HTTP/2 stream shutdown httpd: Out of bounds read in mod_cache_socache can allow a remote attacker to cause DoS httpd: Weak Digest auth nonce generation in mod_auth_digest httpd: mod_http2: Too much time allocated to workers, possibly leading to DoS mod_jk: connector path traversal due to mishandled HTTP requests in httpd httpd: DoS for HTTP/2 connections by continuous SETTINGS frames nghttp2: Null pointer dereference when too large ALTSVC frame is received&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libdb: Reads DB_CONFIG from the current working directory httpd: Out of bounds write in mod_authnz_ldap when using too small Accept-Language values httpd: &amp;lt;FilesMatch&amp;gt; bypass with a trailing newline in the file name openssl: Handling of crafted recursive ASN.1 structures can cause a stack overflow and resulting denial of service httpd: Improper handling of headers in mod_session can allow a remote user to modify session data for CGI applications httpd: Out of bounds access after failure in reading the HTTP request httpd: Use-after-free on HTTP/2 stream shutdown httpd: Out of bounds read in mod_cache_socache can allow a remote attacker to cause DoS httpd: Weak Digest auth nonce generation in mod_auth_digest httpd: mod_http2: Too much time allocated to workers, possibly leading to DoS mod_jk: connector path traversal due to mishandled HTTP requests in httpd httpd: DoS for HTTP/2 connections by continuous SETTINGS frames nghttp2: Null pointer dereference when too large ALTSVC frame is received&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2019:0366</guid>
    </item>
    <item>
      <title>SUSE-SU-2018:3963-2 — Security update for apache2-mod_jk</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2018:3963-2</link>
      <description>&lt;p&gt;Security update for apache2-mod_jk&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache2-mod_jk&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2018:3963-2</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2018-11759</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-11759</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: libapache-mod-jk&lt;/p&gt;
&lt;p&gt;The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. It was also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. While there is some overlap between this issue and CVE-2018-1323, they are not identical.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: libapache-mod-jk&lt;/p&gt;
&lt;p&gt;The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. It was also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. While there is some overlap between this issue and CVE-2018-1323, they are not identical.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-11759</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2984 — Apache Tomcat JK Connector: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2984</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Tomcat JK Connector ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Tomcat JK Connector ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2984</guid>
    </item>
  </channel>
</rss>
