<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:52:53 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:7647 — Moderate: httpd:2.4 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:7647</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: httpd, AlmaLinux:8: httpd-devel, AlmaLinux:8: httpd-filesystem, AlmaLinux:8: httpd-manual, AlmaLinux:8: httpd-tools, AlmaLinux:8: mod_http2, AlmaLinux:8: mod_ldap, AlmaLinux:8: mod_md, AlmaLinux:8: mod_proxy_html, AlmaLinux:8: mod_session and 1 more&lt;/p&gt;
&lt;p&gt;The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: mod_sed: Read/write beyond bounds (CVE-2022-23943)
* httpd: mod_lua: Use of uninitialized value of in r:parsebody (CVE-2022-22719)
* httpd: core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody (CVE-2022-22721)
* httpd: mod_proxy_ajp: Possible request smuggling (CVE-2022-26377)
* httpd: mod_lua: DoS in r:parsebody (CVE-2022-29404)
* httpd: mod_sed: DoS vulnerability (CVE-2022-30522)
* httpd: mod_proxy: X-Forwarded-For dropped by hop-by-hop mechanism (CVE-2022-31813)
* httpd: Out-of-bounds read via ap_rwrite() (CVE-2022-28614)
* httpd: Out-of-bounds read in ap_strcmp_match() (CVE-2022-28615)
* httpd: mod_lua: Information disclosure with websockets (CVE-2022-30556)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: httpd, AlmaLinux:8: httpd-devel, AlmaLinux:8: httpd-filesystem, AlmaLinux:8: httpd-manual, AlmaLinux:8: httpd-tools, AlmaLinux:8: mod_http2, AlmaLinux:8: mod_ldap, AlmaLinux:8: mod_md, AlmaLinux:8: mod_proxy_html, AlmaLinux:8: mod_session and 1 more&lt;/p&gt;
&lt;p&gt;The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: mod_sed: Read/write beyond bounds (CVE-2022-23943)
* httpd: mod_lua: Use of uninitialized value of in r:parsebody (CVE-2022-22719)
* httpd: core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody (CVE-2022-22721)
* httpd: mod_proxy_ajp: Possible request smuggling (CVE-2022-26377)
* httpd: mod_lua: DoS in r:parsebody (CVE-2022-29404)
* httpd: mod_sed: DoS vulnerability (CVE-2022-30522)
* httpd: mod_proxy: X-Forwarded-For dropped by hop-by-hop mechanism (CVE-2022-31813)
* httpd: Out-of-bounds read via ap_rwrite() (CVE-2022-28614)
* httpd: Out-of-bounds read in ap_strcmp_match() (CVE-2022-28615)
* httpd: mod_lua: Information disclosure with websockets (CVE-2022-30556)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:7647</guid>
    </item>
    <item>
      <title>bdu:2022-04145</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-04145</link>
      <description>bdu:2022-04145</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-04145</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2022-30522 — CVE-2022-30522 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2022-30522</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2022-30522</guid>
    </item>
    <item>
      <title>BIT-apache-2022-30522 — mod_sed denial of service</title>
      <link>https://cve.radiocsirt.org/vuln/bit-apache-2022-30522</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apache&lt;/p&gt;
&lt;p&gt;If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apache&lt;/p&gt;
&lt;p&gt;If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-apache-2022-30522</guid>
    </item>
    <item>
      <title>certfr-2022-avi-531 — De multiples vulnérabilités ont été découvertes dans Apache HTTP Server.
Certaines d'entre elles permettent à un attaqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-531</link>
      <description>certfr-2022-avi-531</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-531</guid>
    </item>
    <item>
      <title>EUVD-2026-16535</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-16535</link>
      <description>EUVD-2026-16535</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-16535</guid>
    </item>
    <item>
      <title>fkie_cve-2022-30522</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-30522</link>
      <description>&lt;p&gt;If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-30522</guid>
    </item>
    <item>
      <title>GHSA-jwh2-hhpr-vq5r</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jwh2-hhpr-vq5r</link>
      <description>&lt;p&gt;If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jwh2-hhpr-vq5r</guid>
    </item>
    <item>
      <title>gsd-2022-30522</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-30522</link>
      <description>gsd-2022-30522</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-30522</guid>
    </item>
    <item>
      <title>ICSA-25-133-01 — Hitachi Energy Service Suite</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-133-01</link>
      <description>&lt;p&gt;Hitachi Energy is aware of the multiple vulnerabilities related to open-source Apache Tomcat components that affect the Service Suite product versions listed in this document. An attacker successfully exploiting these
vulnerabilities can cause confidentiality, integrity and availability impacts.
Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Hitachi Energy is aware of the multiple vulnerabilities related to open-source Apache Tomcat components that affect the Service Suite product versions listed in this document. An attacker successfully exploiting these
vulnerabilities can cause confidentiality, integrity and availability impacts.
Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-133-01</guid>
    </item>
    <item>
      <title>OESA-2022-1718 — httpd security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1718</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: httpd, openEuler:20.03-LTS-SP3: httpd, openEuler:22.03-LTS: httpd&lt;/p&gt;
&lt;p&gt;Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Inconsistent Interpretation of HTTP Requests (&amp;amp;apos;HTTP Request Smuggling&amp;amp;apos;) vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.(CVE-2022-26377)&#13;
&#13;
The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts() function. Modules compiled and distributed separately from Apache HTTP Server that use the &amp;amp;apos;ap_rputs&amp;amp;apos; function and may pass it a very large (INT_MAX or larger) string must be compiled against current headers to resolve the issue.(CVE-2022-28614)&#13;
&#13;
Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua scripts that use ap_strcmp_match() may hypothetically be affected.(CVE-2022-28615)&#13;
&#13;
In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size.(CVE-2022-29404)&#13;
&#13;
Apache HTTP Server 2.4.5…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: httpd, openEuler:20.03-LTS-SP3: httpd, openEuler:22.03-LTS: httpd&lt;/p&gt;
&lt;p&gt;Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Inconsistent Interpretation of HTTP Requests (&amp;amp;apos;HTTP Request Smuggling&amp;amp;apos;) vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.(CVE-2022-26377)&#13;
&#13;
The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts() function. Modules compiled and distributed separately from Apache HTTP Server that use the &amp;amp;apos;ap_rputs&amp;amp;apos; function and may pass it a very large (INT_MAX or larger) string must be compiled against current headers to resolve the issue.(CVE-2022-28614)&#13;
&#13;
Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua scripts that use ap_strcmp_match() may hypothetically be affected.(CVE-2022-28615)&#13;
&#13;
In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size.(CVE-2022-29404)&#13;
&#13;
Apache HTTP Server 2.4.5…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1718</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12142-1 — apache2-2.4.54-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12142-1</link>
      <description>&lt;p&gt;apache2-2.4.54-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apache2-2.4.54-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12142-1</guid>
    </item>
    <item>
      <title>RHSA-2022:6753 — Red Hat Security Advisory: httpd24-httpd security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:6753</link>
      <description>&lt;p&gt;httpd: Request splitting via HTTP/2 method injection and mod_proxy httpd: NULL pointer dereference via malformed requests httpd: mod_proxy_uwsgi: out-of-bounds read via a crafted request uri-path httpd: Out-of-bounds write in ap_escape_quotes() via malicious input httpd: possible NULL dereference or SSRF in forward proxy configurations httpd: mod_lua: Use of uninitialized value of in r:parsebody httpd: core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody httpd: mod_sed: Read/write beyond bounds httpd: mod_proxy_ajp: Possible request smuggling httpd: Out-of-bounds read via ap_rwrite() httpd: Out-of-bounds read in ap_strcmp_match() httpd: mod_lua: DoS in r:parsebody httpd: mod_sed: DoS vulnerability httpd: mod_lua: Information disclosure with websockets httpd: mod_proxy: X-Forwarded-For dropped by hop-by-hop mechanism&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;httpd: Request splitting via HTTP/2 method injection and mod_proxy httpd: NULL pointer dereference via malformed requests httpd: mod_proxy_uwsgi: out-of-bounds read via a crafted request uri-path httpd: Out-of-bounds write in ap_escape_quotes() via malicious input httpd: possible NULL dereference or SSRF in forward proxy configurations httpd: mod_lua: Use of uninitialized value of in r:parsebody httpd: core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody httpd: mod_sed: Read/write beyond bounds httpd: mod_proxy_ajp: Possible request smuggling httpd: Out-of-bounds read via ap_rwrite() httpd: Out-of-bounds read in ap_strcmp_match() httpd: mod_lua: DoS in r:parsebody httpd: mod_sed: DoS vulnerability httpd: mod_lua: Information disclosure with websockets httpd: mod_proxy: X-Forwarded-For dropped by hop-by-hop mechanism&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:6753</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:2099-1 — Security update for apache2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:2099-1</link>
      <description>&lt;p&gt;Security update for apache2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:2099-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-30522</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-30522</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: apache2, Ubuntu:Pro:16.04:LTS: apache2, Ubuntu:18.04:LTS: apache2, Ubuntu:20.04:LTS: apache2, Ubuntu:22.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: apache2, Ubuntu:Pro:16.04:LTS: apache2, Ubuntu:18.04:LTS: apache2, Ubuntu:20.04:LTS: apache2, Ubuntu:22.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-30522</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0192 — Apache HTTP Server: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0192</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Apache HTTP Server ausnutzen, um falsche Informationen darzustellen, vertrauliche Informationen offenzulegen, einen Denial of Service Zustand herzustellen und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Apache HTTP Server ausnutzen, um falsche Informationen darzustellen, vertrauliche Informationen offenzulegen, einen Denial of Service Zustand herzustellen und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0192</guid>
    </item>
  </channel>
</rss>
