<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:12:04 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:41906 — Important: httpd security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:41906</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: httpd, AlmaLinux:9: httpd-core, AlmaLinux:9: httpd-devel, AlmaLinux:9: httpd-filesystem, AlmaLinux:9: httpd-manual, AlmaLinux:9: httpd-tools, AlmaLinux:9: mod_ldap, AlmaLinux:9: mod_lua, AlmaLinux:9: mod_proxy_html, AlmaLinux:9: mod_session and 1 more&lt;/p&gt;
&lt;p&gt;The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516)
  * Apache HTTP Server: mod_rewrite: Apache HTTP Server: Privilege Escalation via .htaccess file manipulation (CVE-2026-24072)
  * httpd: mod_auth_digest: timing attack allows a bypass of digest authentication (CVE-2026-33006)
  * httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169)
  * httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356)
  * httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
  * httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631)
  * httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186)
  * httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue (CVE-2026-42535)
  * httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536)
  * httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355)
  * httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime (CVE-2026-43951)
  * httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges (CVE-2026-44119)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: httpd, AlmaLinux:9: httpd-core, AlmaLinux:9: httpd-devel, AlmaLinux:9: httpd-filesystem, AlmaLinux:9: httpd-manual, AlmaLinux:9: httpd-tools, AlmaLinux:9: mod_ldap, AlmaLinux:9: mod_lua, AlmaLinux:9: mod_proxy_html, AlmaLinux:9: mod_session and 1 more&lt;/p&gt;
&lt;p&gt;The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516)
  * Apache HTTP Server: mod_rewrite: Apache HTTP Server: Privilege Escalation via .htaccess file manipulation (CVE-2026-24072)
  * httpd: mod_auth_digest: timing attack allows a bypass of digest authentication (CVE-2026-33006)
  * httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169)
  * httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356)
  * httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
  * httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631)
  * httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186)
  * httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue (CVE-2026-42535)
  * httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536)
  * httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355)
  * httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime (CVE-2026-43951)
  * httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges (CVE-2026-44119)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:41906</guid>
    </item>
    <item>
      <title>bdu:2026-06354</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-06354</link>
      <description>bdu:2026-06354</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-06354</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-24072</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-24072</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: apache2, Alpaquita:25: apache2, Alpaquita:stream: apache2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: apache2, Alpaquita:25: apache2, Alpaquita:stream: apache2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-24072</guid>
    </item>
    <item>
      <title>BIT-apache-2026-24072 — Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr</title>
      <link>https://cve.radiocsirt.org/vuln/bit-apache-2026-24072</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apache&lt;/p&gt;
&lt;p&gt;An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apache&lt;/p&gt;
&lt;p&gt;An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-apache-2026-24072</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0530 — De multiples vulnérabilités ont été découvertes dans Apache HTTP Server. Certaines d'entre elles permettent à un attaqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0530</link>
      <description>certfr-2026-avi-0530</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0530</guid>
    </item>
    <item>
      <title>cnvd-2026-21691</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-21691</link>
      <description>cnvd-2026-21691</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-21691</guid>
    </item>
    <item>
      <title>EUVD-2026-308509</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-308509</link>
      <description>EUVD-2026-308509</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-308509</guid>
    </item>
    <item>
      <title>fkie_cve-2026-24072</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-24072</link>
      <description>&lt;p&gt;An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-24072</guid>
    </item>
    <item>
      <title>GHSA-9pw3-5ggm-c92r</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9pw3-5ggm-c92r</link>
      <description>&lt;p&gt;An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9pw3-5ggm-c92r</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-24072 — Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-24072</link>
      <description>msrc_CVE-2026-24072</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-24072</guid>
    </item>
    <item>
      <title>NCSC-2026-0134 — Kwetsbaarheden verholpen in Apache HTTP Server</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0134</link>
      <description>NCSC-2026-0134</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0134</guid>
    </item>
    <item>
      <title>OESA-2026-2316 — httpd security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2316</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: httpd&lt;/p&gt;
&lt;p&gt;Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes this issue.(CVE-2026-24072)&lt;/p&gt;
&lt;p&gt;Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.
If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: through 2.4.66.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-28780)&lt;/p&gt;
&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server&amp;amp;apos;s  mod_md via OCSP response data.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-29168)&lt;/p&gt;
&lt;p&gt;A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs.&lt;/p&gt;
&lt;p&gt;The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: httpd&lt;/p&gt;
&lt;p&gt;Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes this issue.(CVE-2026-24072)&lt;/p&gt;
&lt;p&gt;Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.
If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: through 2.4.66.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-28780)&lt;/p&gt;
&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server&amp;amp;apos;s  mod_md via OCSP response data.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-29168)&lt;/p&gt;
&lt;p&gt;A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs.&lt;/p&gt;
&lt;p&gt;The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2316</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10785-1 — apache2-2.4.67-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10785-1</link>
      <description>&lt;p&gt;apache2-2.4.67-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apache2-2.4.67-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10785-1</guid>
    </item>
    <item>
      <title>RHSA-2026:13938 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:13938</link>
      <description>&lt;p&gt;Apache HTTP Server: Apache HTTP Server: Remote Code Execution via Double Free in HTTP/2 Protocol Apache HTTP Server: mod_rewrite: Apache HTTP Server: Privilege Escalation via .htaccess file manipulation httpd: mod_authn_socache: NULL pointer dereference can cause a child process crash httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check httpd: mod_proxy_ajp: heap-based buffer over-read and memory disclosure in ajp_parse_data()&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache HTTP Server: Apache HTTP Server: Remote Code Execution via Double Free in HTTP/2 Protocol Apache HTTP Server: mod_rewrite: Apache HTTP Server: Privilege Escalation via .htaccess file manipulation httpd: mod_authn_socache: NULL pointer dereference can cause a child process crash httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check httpd: mod_proxy_ajp: heap-based buffer over-read and memory disclosure in ajp_parse_data()&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:13938</guid>
    </item>
    <item>
      <title>RLSA-2026:34109 — Important: httpd security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:34109</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: httpd&lt;/p&gt;
&lt;p&gt;The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516)&lt;/p&gt;
&lt;p&gt;* httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169)&lt;/p&gt;
&lt;p&gt;* httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356)&lt;/p&gt;
&lt;p&gt;* httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185)&lt;/p&gt;
&lt;p&gt;* httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631)&lt;/p&gt;
&lt;p&gt;* httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536)&lt;/p&gt;
&lt;p&gt;* httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* address Moderate severity issues from httpd 2.4.68 [rhel-10.2.z] (JIRA:Rocky Linux-184518)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: httpd&lt;/p&gt;
&lt;p&gt;The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516)&lt;/p&gt;
&lt;p&gt;* httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169)&lt;/p&gt;
&lt;p&gt;* httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356)&lt;/p&gt;
&lt;p&gt;* httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185)&lt;/p&gt;
&lt;p&gt;* httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631)&lt;/p&gt;
&lt;p&gt;* httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536)&lt;/p&gt;
&lt;p&gt;* httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* address Moderate severity issues from httpd 2.4.68 [rhel-10.2.z] (JIRA:Rocky Linux-184518)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:34109</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:2103-1 — Security update for apache2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:2103-1</link>
      <description>&lt;p&gt;Security update for apache2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:2103-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-24072</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-24072</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: apache2, Ubuntu:Pro:16.04:LTS: apache2, Ubuntu:Pro:18.04:LTS: apache2, Ubuntu:Pro:20.04:LTS: apache2, Ubuntu:22.04:LTS: apache2, Ubuntu:24.04:LTS: apache2, Ubuntu:25.10: apache2, Ubuntu:26.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which fixes this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: apache2, Ubuntu:Pro:16.04:LTS: apache2, Ubuntu:Pro:18.04:LTS: apache2, Ubuntu:Pro:20.04:LTS: apache2, Ubuntu:22.04:LTS: apache2, Ubuntu:24.04:LTS: apache2, Ubuntu:25.10: apache2, Ubuntu:26.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which fixes this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-24072</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1354 — Apache HTTP Server: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1354</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apache HTTP Server ausnutzen, um erweiterte Privilegien zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apache HTTP Server ausnutzen, um erweiterte Privilegien zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1354</guid>
    </item>
  </channel>
</rss>
