<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 02:57:30 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:14625 — Moderate: mod_http2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:14625</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: mod_http2&lt;/p&gt;
&lt;p&gt;The mod_h2 Apache httpd module implements the HTTP2 protocol (h2+h2c) on top of libnghttp2 for httpd 2.4 servers.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: mod_proxy_http2: untrusted input from a client causes an assertion to fail in the Apache mod_proxy_http2 module (CVE-2025-49630)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: mod_http2&lt;/p&gt;
&lt;p&gt;The mod_h2 Apache httpd module implements the HTTP2 protocol (h2+h2c) on top of libnghttp2 for httpd 2.4 servers.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: mod_proxy_http2: untrusted input from a client causes an assertion to fail in the Apache mod_proxy_http2 module (CVE-2025-49630)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:14625</guid>
    </item>
    <item>
      <title>bdu:2025-08695</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-08695</link>
      <description>bdu:2025-08695</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-08695</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-49630</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-49630</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: apache2, Alpaquita:25: apache2, Alpaquita:stream: apache2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: apache2, Alpaquita:25: apache2, Alpaquita:stream: apache2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-49630</guid>
    </item>
    <item>
      <title>BIT-apache-2025-49630 — Apache HTTP Server: mod_proxy_http2 denial of service</title>
      <link>https://cve.radiocsirt.org/vuln/bit-apache-2025-49630</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apache&lt;/p&gt;
&lt;p&gt;In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2.&lt;/p&gt;
&lt;p&gt;Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to &amp;#34;on&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apache&lt;/p&gt;
&lt;p&gt;In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2.&lt;/p&gt;
&lt;p&gt;Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to &amp;#34;on&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-apache-2025-49630</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0586 — De multiples vulnérabilités ont été découvertes dans Apache HTTP Server. Certaines d'entre elles permettent à un attaqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0586</link>
      <description>certfr-2025-avi-0586</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0586</guid>
    </item>
    <item>
      <title>cnvd-2025-16603</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2025-16603</link>
      <description>cnvd-2025-16603</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2025-16603</guid>
    </item>
    <item>
      <title>EUVD-2026-259970</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-259970</link>
      <description>EUVD-2026-259970</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-259970</guid>
    </item>
    <item>
      <title>fkie_cve-2025-49630</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-49630</link>
      <description>&lt;p&gt;In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2.&lt;/p&gt;
&lt;p&gt;Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to &amp;#34;on&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2.&lt;/p&gt;
&lt;p&gt;Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to &amp;#34;on&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-49630</guid>
    </item>
    <item>
      <title>GHSA-72h2-3r97-f454</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-72h2-3r97-f454</link>
      <description>&lt;p&gt;In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2.&lt;/p&gt;
&lt;p&gt;Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to &amp;#34;on&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2.&lt;/p&gt;
&lt;p&gt;Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to &amp;#34;on&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-72h2-3r97-f454</guid>
    </item>
    <item>
      <title>jvndb-2026-003910</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2026-003910</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been found in Cosminexus HTTP Server.&#13;
&#13;
CVE-2025-49630, CVE-2025-53020&#13;
&#13;
These vulnerabilities does not apply if HTTP/2 protocol is disabled.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been found in Cosminexus HTTP Server.&#13;
&#13;
CVE-2025-49630, CVE-2025-53020&#13;
&#13;
These vulnerabilities does not apply if HTTP/2 protocol is disabled.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2026-003910</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-49630 — Apache HTTP Server: mod_proxy_http2 denial of service</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-49630</link>
      <description>msrc_CVE-2025-49630</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-49630</guid>
    </item>
    <item>
      <title>OESA-2025-2076 — mod_http2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2076</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: mod_http2, openEuler:22.03-LTS-SP4: mod_http2, openEuler:24.03-LTS: mod_http2, openEuler:24.03-LTS-SP1: mod_http2, openEuler:24.03-LTS-SP2: mod_http2, openEuler:20.03-LTS-SP4: mod_http2&lt;/p&gt;
&lt;p&gt;The mod_h2 Apache httpd module implements the HTTP2 protocol (h2+h2c) on top of libnghttp2 for httpd 2.4 servers.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability classified as problematic has been found in Apache HTTP Server up to 2.4.63 (Web Server).CWE is classifying the issue as CWE-617. The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.This is going to have an impact on availability.Upgrading to version 2.4.64 eliminates this vulnerability.The vulnerability is also documented in the vulnerability database at EUVD (EUVD-2025-21017).(CVE-2025-49630)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: mod_http2, openEuler:22.03-LTS-SP4: mod_http2, openEuler:24.03-LTS: mod_http2, openEuler:24.03-LTS-SP1: mod_http2, openEuler:24.03-LTS-SP2: mod_http2, openEuler:20.03-LTS-SP4: mod_http2&lt;/p&gt;
&lt;p&gt;The mod_h2 Apache httpd module implements the HTTP2 protocol (h2+h2c) on top of libnghttp2 for httpd 2.4 servers.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability classified as problematic has been found in Apache HTTP Server up to 2.4.63 (Web Server).CWE is classifying the issue as CWE-617. The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.This is going to have an impact on availability.Upgrading to version 2.4.64 eliminates this vulnerability.The vulnerability is also documented in the vulnerability database at EUVD (EUVD-2025-21017).(CVE-2025-49630)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2076</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15360-1 — apache2-2.4.64-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15360-1</link>
      <description>&lt;p&gt;apache2-2.4.64-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apache2-2.4.64-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15360-1</guid>
    </item>
    <item>
      <title>RHSA-2025:13680 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.62 SP1 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:13680</link>
      <description>&lt;p&gt;httpd: insufficient escaping of user-supplied data in mod_ssl httpd: mod_ssl: access control bypass by trusted clients is possible using TLS 1.3 session resumption modsecurity: ModSecurity Has Possible DoS Vulnerability httpd: mod_proxy_http2: untrusted input from a client causes an assertion to fail in the Apache mod_proxy_http2 module httpd: HTTP Session Hijack via a TLS upgrade&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;httpd: insufficient escaping of user-supplied data in mod_ssl httpd: mod_ssl: access control bypass by trusted clients is possible using TLS 1.3 session resumption modsecurity: ModSecurity Has Possible DoS Vulnerability httpd: mod_proxy_http2: untrusted input from a client causes an assertion to fail in the Apache mod_proxy_http2 module httpd: HTTP Session Hijack via a TLS upgrade&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:13680</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:02565-1 — Security update for apache2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:02565-1</link>
      <description>&lt;p&gt;Security update for apache2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:02565-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-49630</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-49630</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: apache2, Ubuntu:Pro:20.04:LTS: apache2, Ubuntu:22.04:LTS: apache2, Ubuntu:24.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to &amp;#34;on&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: apache2, Ubuntu:Pro:20.04:LTS: apache2, Ubuntu:22.04:LTS: apache2, Ubuntu:24.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to &amp;#34;on&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-49630</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1529 — Apache HTTP Server: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1529</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apache HTTP Server ausnutzen, um einen Denial of Service Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, und um Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apache HTTP Server ausnutzen, um einen Denial of Service Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, und um Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1529</guid>
    </item>
  </channel>
</rss>
