<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:22:16 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:41906 — Important: httpd security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:41906</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: httpd, AlmaLinux:9: httpd-core, AlmaLinux:9: httpd-devel, AlmaLinux:9: httpd-filesystem, AlmaLinux:9: httpd-manual, AlmaLinux:9: httpd-tools, AlmaLinux:9: mod_ldap, AlmaLinux:9: mod_lua, AlmaLinux:9: mod_proxy_html, AlmaLinux:9: mod_session and 1 more&lt;/p&gt;
&lt;p&gt;The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516)
  * Apache HTTP Server: mod_rewrite: Apache HTTP Server: Privilege Escalation via .htaccess file manipulation (CVE-2026-24072)
  * httpd: mod_auth_digest: timing attack allows a bypass of digest authentication (CVE-2026-33006)
  * httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169)
  * httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356)
  * httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
  * httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631)
  * httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186)
  * httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue (CVE-2026-42535)
  * httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536)
  * httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355)
  * httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime (CVE-2026-43951)
  * httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges (CVE-2026-44119)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: httpd, AlmaLinux:9: httpd-core, AlmaLinux:9: httpd-devel, AlmaLinux:9: httpd-filesystem, AlmaLinux:9: httpd-manual, AlmaLinux:9: httpd-tools, AlmaLinux:9: mod_ldap, AlmaLinux:9: mod_lua, AlmaLinux:9: mod_proxy_html, AlmaLinux:9: mod_session and 1 more&lt;/p&gt;
&lt;p&gt;The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516)
  * Apache HTTP Server: mod_rewrite: Apache HTTP Server: Privilege Escalation via .htaccess file manipulation (CVE-2026-24072)
  * httpd: mod_auth_digest: timing attack allows a bypass of digest authentication (CVE-2026-33006)
  * httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169)
  * httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356)
  * httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
  * httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631)
  * httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186)
  * httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue (CVE-2026-42535)
  * httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536)
  * httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355)
  * httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime (CVE-2026-43951)
  * httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges (CVE-2026-44119)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:41906</guid>
    </item>
    <item>
      <title>bdu:2026-12017</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-12017</link>
      <description>bdu:2026-12017</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-12017</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-44119</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-44119</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: apache2, Alpaquita:25: apache2, Alpaquita:stream: apache2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: apache2, Alpaquita:25: apache2, Alpaquita:stream: apache2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-44119</guid>
    </item>
    <item>
      <title>BIT-apache-2026-44119 — Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules</title>
      <link>https://cve.radiocsirt.org/vuln/bit-apache-2026-44119</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apache&lt;/p&gt;
&lt;p&gt;Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: from through 2.4.67.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.68, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apache&lt;/p&gt;
&lt;p&gt;Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: from through 2.4.67.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.68, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-apache-2026-44119</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0710 — De multiples vulnérabilités ont été découvertes dans Apache HTTP Server. Certaines d'entre elles permettent à un attaqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0710</link>
      <description>certfr-2026-avi-0710</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0710</guid>
    </item>
    <item>
      <title>EUVD-2026-325762</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-325762</link>
      <description>EUVD-2026-325762</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-325762</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44119</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44119</link>
      <description>&lt;p&gt;Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: from through 2.4.67.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.68, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: from through 2.4.67.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.68, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44119</guid>
    </item>
    <item>
      <title>GHSA-fm8w-r4qw-vq3r</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fm8w-r4qw-vq3r</link>
      <description>&lt;p&gt;Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: from through 2.4.67.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.68, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: from through 2.4.67.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.68, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fm8w-r4qw-vq3r</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-44119 — Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-44119</link>
      <description>msrc_CVE-2026-44119</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-44119</guid>
    </item>
    <item>
      <title>OESA-2026-2745 — httpd security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2745</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: httpd&lt;/p&gt;
&lt;p&gt;Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.68, which fixes the issue.(CVE-2026-29167)&lt;/p&gt;
&lt;p&gt;A cross-site scripting vulnerability exists in mod_proxy_ftp&amp;amp;apos;s HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.68, which fixes this issue.(CVE-2026-29170)&lt;/p&gt;
&lt;p&gt;A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.(CVE-2026-34355)&lt;/p&gt;
&lt;p&gt;Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie*&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.68, which fixes the issue.(CVE-2026-34356)&lt;/p&gt;
&lt;p&gt;A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.68, which fixes this issue.(CVE-2026-42535)&lt;/p&gt;
&lt;p&gt;Heap-based Buffer Overflow vulnerability…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: httpd&lt;/p&gt;
&lt;p&gt;Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.68, which fixes the issue.(CVE-2026-29167)&lt;/p&gt;
&lt;p&gt;A cross-site scripting vulnerability exists in mod_proxy_ftp&amp;amp;apos;s HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.68, which fixes this issue.(CVE-2026-29170)&lt;/p&gt;
&lt;p&gt;A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.(CVE-2026-34355)&lt;/p&gt;
&lt;p&gt;Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie*&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.68, which fixes the issue.(CVE-2026-34356)&lt;/p&gt;
&lt;p&gt;A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.68, which fixes this issue.(CVE-2026-42535)&lt;/p&gt;
&lt;p&gt;Heap-based Buffer Overflow vulnerability…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2745</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21235-1 — Security update for apache2</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21235-1</link>
      <description>&lt;p&gt;Security update for apache2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21235-1</guid>
    </item>
    <item>
      <title>RHSA-2026:25042 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:25042</link>
      <description>&lt;p&gt;httpd: Apache HTTP Server: Arbitrary code execution or denial of service via use-after-free in mod_ldap per-directory configuration httpd: Apache HTTP Server: Cross-site scripting in mod_proxy_ftp via HTML directory list generation httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server httpd: Apache HTTP Server: Denial of Service via crafted regular expressions httpd: mod_http2: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service. httpd: httpd: HTTP/2 Remote Denial of Service via compression bomb and Slowloris-style attack&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;httpd: Apache HTTP Server: Arbitrary code execution or denial of service via use-after-free in mod_ldap per-directory configuration httpd: Apache HTTP Server: Cross-site scripting in mod_proxy_ftp via HTML directory list generation httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server httpd: Apache HTTP Server: Denial of Service via crafted regular expressions httpd: mod_http2: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service. httpd: httpd: HTTP/2 Remote Denial of Service via compression bomb and Slowloris-style attack&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:25042</guid>
    </item>
    <item>
      <title>RLSA-2026:34109 — Important: httpd security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:34109</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: httpd&lt;/p&gt;
&lt;p&gt;The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516)&lt;/p&gt;
&lt;p&gt;* httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169)&lt;/p&gt;
&lt;p&gt;* httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356)&lt;/p&gt;
&lt;p&gt;* httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185)&lt;/p&gt;
&lt;p&gt;* httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631)&lt;/p&gt;
&lt;p&gt;* httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536)&lt;/p&gt;
&lt;p&gt;* httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* address Moderate severity issues from httpd 2.4.68 [rhel-10.2.z] (JIRA:Rocky Linux-184518)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: httpd&lt;/p&gt;
&lt;p&gt;The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516)&lt;/p&gt;
&lt;p&gt;* httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169)&lt;/p&gt;
&lt;p&gt;* httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356)&lt;/p&gt;
&lt;p&gt;* httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185)&lt;/p&gt;
&lt;p&gt;* httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631)&lt;/p&gt;
&lt;p&gt;* httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536)&lt;/p&gt;
&lt;p&gt;* httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* address Moderate severity issues from httpd 2.4.68 [rhel-10.2.z] (JIRA:Rocky Linux-184518)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:34109</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22564-1 — Security update for apache2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22564-1</link>
      <description>&lt;p&gt;Security update for apache2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22564-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-44119</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44119</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: apache2, Ubuntu:Pro:16.04:LTS: apache2, Ubuntu:Pro:18.04:LTS: apache2, Ubuntu:Pro:20.04:LTS: apache2, Ubuntu:22.04:LTS: apache2, Ubuntu:24.04:LTS: apache2, Ubuntu:25.10: apache2, Ubuntu:26.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. This issue affects Apache HTTP Server: from through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: apache2, Ubuntu:Pro:16.04:LTS: apache2, Ubuntu:Pro:18.04:LTS: apache2, Ubuntu:Pro:20.04:LTS: apache2, Ubuntu:22.04:LTS: apache2, Ubuntu:24.04:LTS: apache2, Ubuntu:25.10: apache2, Ubuntu:26.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. This issue affects Apache HTTP Server: from through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44119</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1824 — Apache HTTP Server: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1824</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apache HTTP Server ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu verändern und offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder andere nicht näher definierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apache HTTP Server ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu verändern und offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder andere nicht näher definierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1824</guid>
    </item>
  </channel>
</rss>
