<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:14:15 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:5138 — Important: httpd security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:5138</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: httpd, AlmaLinux:9: httpd-core, AlmaLinux:9: httpd-devel, AlmaLinux:9: httpd-filesystem, AlmaLinux:9: httpd-manual, AlmaLinux:9: httpd-tools, AlmaLinux:9: mod_ldap, AlmaLinux:9: mod_lua, AlmaLinux:9: mod_proxy_html, AlmaLinux:9: mod_session and 1 more&lt;/p&gt;
&lt;p&gt;The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: Security issues via?backend applications whose response headers are malicious or exploitable (CVE-2024-38476)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: httpd, AlmaLinux:9: httpd-core, AlmaLinux:9: httpd-devel, AlmaLinux:9: httpd-filesystem, AlmaLinux:9: httpd-manual, AlmaLinux:9: httpd-tools, AlmaLinux:9: mod_ldap, AlmaLinux:9: mod_lua, AlmaLinux:9: mod_proxy_html, AlmaLinux:9: mod_session and 1 more&lt;/p&gt;
&lt;p&gt;The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: Security issues via?backend applications whose response headers are malicious or exploitable (CVE-2024-38476)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:5138</guid>
    </item>
    <item>
      <title>bdu:2024-05131</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-05131</link>
      <description>bdu:2024-05131</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-05131</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-38476</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-38476</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: apache2, Alpaquita:stream: apache2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: apache2, Alpaquita:stream: apache2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-38476</guid>
    </item>
    <item>
      <title>BIT-apache-2024-38476 — Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect</title>
      <link>https://cve.radiocsirt.org/vuln/bit-apache-2024-38476</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apache&lt;/p&gt;
&lt;p&gt;Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.60, which fixes this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apache&lt;/p&gt;
&lt;p&gt;Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.60, which fixes this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-apache-2024-38476</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0533 — De multiples vulnérabilités ont été découvertes dans Apache HTTP Server. Certaines d'entre elles permettent à un attaqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0533</link>
      <description>certfr-2024-avi-0533</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0533</guid>
    </item>
    <item>
      <title>cnvd-2024-36391</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2024-36391</link>
      <description>cnvd-2024-36391</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2024-36391</guid>
    </item>
    <item>
      <title>ESSA-2024:0630 — security update for httpd from RHSA-2024:7101</title>
      <link>https://cve.radiocsirt.org/vuln/essa-2024:0630</link>
      <description>&lt;p&gt;security update for httpd from RHSA-2024:7101&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;security update for httpd from RHSA-2024:7101&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/essa-2024:0630</guid>
    </item>
    <item>
      <title>EUVD-2026-258615</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258615</link>
      <description>EUVD-2026-258615</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258615</guid>
    </item>
    <item>
      <title>fkie_cve-2024-38476</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-38476</link>
      <description>&lt;p&gt;Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.60, which fixes this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.60, which fixes this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-38476</guid>
    </item>
    <item>
      <title>GHSA-fpq9-w5cw-5hf8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fpq9-w5cw-5hf8</link>
      <description>&lt;p&gt;Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.60, which fixes this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.60, which fixes this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fpq9-w5cw-5hf8</guid>
    </item>
    <item>
      <title>OESA-2024-2101 — httpd security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2101</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: httpd, openEuler:20.03-LTS-SP4: httpd, openEuler:22.03-LTS-SP1: httpd, openEuler:24.03-LTS: httpd, openEuler:22.03-LTS-SP4: httpd&lt;/p&gt;
&lt;p&gt;Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.60, which fixes this issue.(CVE-2024-38476)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: httpd, openEuler:20.03-LTS-SP4: httpd, openEuler:22.03-LTS-SP1: httpd, openEuler:24.03-LTS: httpd, openEuler:22.03-LTS-SP4: httpd&lt;/p&gt;
&lt;p&gt;Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.60, which fixes this issue.(CVE-2024-38476)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2101</guid>
    </item>
    <item>
      <title>RHSA-2024:5239 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.57 SP5 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:5239</link>
      <description>&lt;p&gt;httpd: Encoding problem in mod_proxy httpd: Substitution encoding issue in mod_rewrite httpd: Improper escaping of output in mod_rewrite httpd: Security issues via backend applications whose response headers are malicious or exploitable httpd: NULL pointer dereference in mod_proxy httpd: Potential SSRF in mod_rewrite&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;httpd: Encoding problem in mod_proxy httpd: Substitution encoding issue in mod_rewrite httpd: Improper escaping of output in mod_rewrite httpd: Security issues via backend applications whose response headers are malicious or exploitable httpd: NULL pointer dereference in mod_proxy httpd: Potential SSRF in mod_rewrite&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:5239</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:2560-1 — Security update for apache2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:2560-1</link>
      <description>&lt;p&gt;Security update for apache2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:2560-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-38476</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-38476</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: apache2, Ubuntu:Pro:16.04:LTS: apache2, Ubuntu:Pro:18.04:LTS: apache2, Ubuntu:20.04:LTS: apache2, Ubuntu:22.04:LTS: apache2, Ubuntu:24.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: apache2, Ubuntu:Pro:16.04:LTS: apache2, Ubuntu:Pro:18.04:LTS: apache2, Ubuntu:20.04:LTS: apache2, Ubuntu:22.04:LTS: apache2, Ubuntu:24.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-38476</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1504 — Apache HTTP Server: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1504</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Apache HTTP Server ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Apache HTTP Server ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1504</guid>
    </item>
  </channel>
</rss>
