<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:38:48 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:30844 — Moderate: mod_md security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:30844</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: mod_md&lt;/p&gt;
&lt;p&gt;This module manages common properties of domains for one or more virtual hosts. Specifically it can use the ACME protocol to automate certificate provisioning. Certificates will be configured for managed domains and their virtual hosts automatically, including at renewal.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: mod_md: unrestricted OCSP response leads to resource exhaustion (CVE-2026-29168)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: mod_md&lt;/p&gt;
&lt;p&gt;This module manages common properties of domains for one or more virtual hosts. Specifically it can use the ACME protocol to automate certificate provisioning. Certificates will be configured for managed domains and their virtual hosts automatically, including at renewal.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: mod_md: unrestricted OCSP response leads to resource exhaustion (CVE-2026-29168)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:30844</guid>
    </item>
    <item>
      <title>bdu:2026-06409</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-06409</link>
      <description>bdu:2026-06409</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-06409</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-29168</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-29168</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: apache2, Alpaquita:25: apache2, Alpaquita:stream: apache2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: apache2, Alpaquita:25: apache2, Alpaquita:stream: apache2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-29168</guid>
    </item>
    <item>
      <title>BIT-apache-2026-29168 — Apache HTTP Server: mod_md unrestricted OCSP response</title>
      <link>https://cve.radiocsirt.org/vuln/bit-apache-2026-29168</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apache&lt;/p&gt;
&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server&amp;#39;s  mod_md via OCSP response data.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apache&lt;/p&gt;
&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server&amp;#39;s  mod_md via OCSP response data.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-apache-2026-29168</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0530 — De multiples vulnérabilités ont été découvertes dans Apache HTTP Server. Certaines d'entre elles permettent à un attaqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0530</link>
      <description>certfr-2026-avi-0530</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0530</guid>
    </item>
    <item>
      <title>cnvd-2026-21700</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-21700</link>
      <description>cnvd-2026-21700</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-21700</guid>
    </item>
    <item>
      <title>EUVD-2026-308603</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-308603</link>
      <description>EUVD-2026-308603</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-308603</guid>
    </item>
    <item>
      <title>fkie_cve-2026-29168</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-29168</link>
      <description>&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server&amp;#39;s  mod_md via OCSP response data.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server&amp;#39;s  mod_md via OCSP response data.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-29168</guid>
    </item>
    <item>
      <title>GHSA-h688-wmf2-q99q</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h688-wmf2-q99q</link>
      <description>&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server&amp;#39;s  mod_md via OCSP response data.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server&amp;#39;s  mod_md via OCSP response data.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h688-wmf2-q99q</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-29168 — Apache HTTP Server: mod_md unrestricted OCSP response</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-29168</link>
      <description>msrc_CVE-2026-29168</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-29168</guid>
    </item>
    <item>
      <title>NCSC-2026-0134 — Kwetsbaarheden verholpen in Apache HTTP Server</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0134</link>
      <description>NCSC-2026-0134</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0134</guid>
    </item>
    <item>
      <title>OESA-2026-2316 — httpd security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2316</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: httpd&lt;/p&gt;
&lt;p&gt;Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes this issue.(CVE-2026-24072)&lt;/p&gt;
&lt;p&gt;Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.
If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: through 2.4.66.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-28780)&lt;/p&gt;
&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server&amp;amp;apos;s  mod_md via OCSP response data.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-29168)&lt;/p&gt;
&lt;p&gt;A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs.&lt;/p&gt;
&lt;p&gt;The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: httpd&lt;/p&gt;
&lt;p&gt;Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes this issue.(CVE-2026-24072)&lt;/p&gt;
&lt;p&gt;Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.
If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: through 2.4.66.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-28780)&lt;/p&gt;
&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server&amp;amp;apos;s  mod_md via OCSP response data.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-29168)&lt;/p&gt;
&lt;p&gt;A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs.&lt;/p&gt;
&lt;p&gt;The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2316</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10785-1 — apache2-2.4.67-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10785-1</link>
      <description>&lt;p&gt;apache2-2.4.67-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apache2-2.4.67-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10785-1</guid>
    </item>
    <item>
      <title>RHSA-2026:27200 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.62 SP4 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:27200</link>
      <description>&lt;p&gt;mod_http2: Apache HTTP Server: HTTP/2 DoS by Memory Increase nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow httpd: mod_md: unrestricted OCSP response leads to resource exhaustion httpd: NULL pointer dereference via specially crafted request httpd: mod_authn_socache: NULL pointer dereference can cause a child process crash httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check httpd: mod_proxy_ajp: heap-based buffer over-read and memory disclosure in ajp_parse_data() httpd: httpd: HTTP/2 Remote Denial of Service via compression bomb and Slowloris-style attack&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;mod_http2: Apache HTTP Server: HTTP/2 DoS by Memory Increase nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow httpd: mod_md: unrestricted OCSP response leads to resource exhaustion httpd: NULL pointer dereference via specially crafted request httpd: mod_authn_socache: NULL pointer dereference can cause a child process crash httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check httpd: mod_proxy_ajp: heap-based buffer over-read and memory disclosure in ajp_parse_data() httpd: httpd: HTTP/2 Remote Denial of Service via compression bomb and Slowloris-style attack&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:27200</guid>
    </item>
    <item>
      <title>RLSA-2026:30844 — Moderate: mod_md security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:30844</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: mod_md&lt;/p&gt;
&lt;p&gt;This module manages common properties of domains for one or more virtual hosts. Specifically it can use the ACME protocol to automate certificate provisioning.  Certificates will be configured for managed domains and their virtual hosts automatically, including at renewal.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: mod_md: unrestricted OCSP response leads to resource exhaustion (CVE-2026-29168)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: mod_md&lt;/p&gt;
&lt;p&gt;This module manages common properties of domains for one or more virtual hosts. Specifically it can use the ACME protocol to automate certificate provisioning.  Certificates will be configured for managed domains and their virtual hosts automatically, including at renewal.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: mod_md: unrestricted OCSP response leads to resource exhaustion (CVE-2026-29168)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:30844</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:2103-1 — Security update for apache2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:2103-1</link>
      <description>&lt;p&gt;Security update for apache2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:2103-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-29168</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-29168</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: apache2, Ubuntu:24.04:LTS: apache2, Ubuntu:25.10: apache2, Ubuntu:26.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server&amp;#39;s  mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: apache2, Ubuntu:24.04:LTS: apache2, Ubuntu:25.10: apache2, Ubuntu:26.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server&amp;#39;s  mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-29168</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1354 — Apache HTTP Server: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1354</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apache HTTP Server ausnutzen, um erweiterte Privilegien zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apache HTTP Server ausnutzen, um erweiterte Privilegien zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1354</guid>
    </item>
  </channel>
</rss>
