(httpd-site) branch asf-site updated: Automatic Site Publish by Buildbot

[email protected] Thu, 04 Jun 2026 16:37:09 +0000
Newsgroups gmane.comp.apache.cvs
Message-ID <178059102954.2007810.12687511904123348019@gitbox3-he-fi.apache.org>
This is an automated email from the ASF dual-hosted git repository.

asf-gitbox-commits pushed a commit to branch asf-site
in repository https://gitbox.apache.org/repos/asf/httpd-site.git


The following commit(s) were added to refs/heads/asf-site by this push:
     new 94dd364  Automatic Site Publish by Buildbot
94dd364 is described below

commit 94dd36487d0c9045b99f119194c785934edbe6ab
Author: buildbot <[email protected]>
AuthorDate: Thu Jun 4 16:37:05 2026 +0000

    Automatic Site Publish by Buildbot
---
 output/security/json/CVE-2026-34032.json   |  5 +++++
 output/security/vulnerabilities-httpd.json |  5 +++++
 output/security/vulnerabilities_24.html    | 14 ++++++++++++++
 3 files changed, 24 insertions(+)

diff --git a/output/security/json/CVE-2026-34032.json b/output/security/json/CVE-2026-34032.json
index 9517c74..2b4c326 100644
--- a/output/security/json/CVE-2026-34032.json
+++ b/output/security/json/CVE-2026-34032.json
@@ -101,6 +101,11 @@
                     "time": "2026-05-04T12:00:00.000Z",
                     "lang": "en",
                     "value": "fixed in 2.4.x by r1933343"
+                },
+                {
+                    "time": "2026-05-04T00:00:00.000Z",
+                    "lang": "en",
+                    "value": "2.4.67 released"
                 }
             ],
             "credits": [
diff --git a/output/security/vulnerabilities-httpd.json b/output/security/vulnerabilities-httpd.json
index 6d85781..38a71c7 100644
--- a/output/security/vulnerabilities-httpd.json
+++ b/output/security/vulnerabilities-httpd.json
@@ -24466,6 +24466,11 @@
                         "time": "2026-05-04T12:00:00.000Z",
                         "lang": "en",
                         "value": "fixed in 2.4.x by r1933343"
+                    },
+                    {
+                        "time": "2026-05-04T00:00:00.000Z",
+                        "lang": "en",
+                        "value": "2.4.67 released"
                     }
                 ],
                 "credits": [
diff --git a/output/security/vulnerabilities_24.html b/output/security/vulnerabilities_24.html
index bfb0a95..6618549 100644
--- a/output/security/vulnerabilities_24.html
+++ b/output/security/vulnerabilities_24.html
@@ -192,6 +192,20 @@ h1:hover > .headerlink, h2:hover > .headerlink, h3:hover > .headerlink, h4:hover
 <tr><td class="cve-header">Update 2.4.67 released</td><td class="cve-value">2026-05-04</td></tr>
 <tr><td class="cve-header">Affects</td><td class="cve-value"> through 2.4.66</td></tr>
 </table></dd>
+<dt><h3 id="CVE-2026-34032">low: <name name="CVE-2026-34032">mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string)</name>
+(<a href="https://www.cve.org/CVERecord?id=CVE-2026-34032">CVE-2026-34032</a>)</h3></dt>
+<dd><p>Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server.</p><p></p><p>This issue affects Apache HTTP Server: through 2.4.66.</p><p></p><p>Users are recommended to upgrade to version 2.4.67, which fixes the issue.</p>
+<p>Acknowledgements:</p>
+<ul>
+<li>finder: Tianshuo Han (&lt;[email protected]&gt;)</li>
+<li>finder: J&eacute;r&ocirc;me Djouder</li>
+<li>finder: Sajeeb Lohani working with TrendAI Zero Day Initiative</li>
+</ul>
+<table class="table"><tr><td class="cve-header">Report received</td><td class="cve-value">2026-03-01</td></tr>
+<tr><td class="cve-header">fixed in 2.4.x by r1933343</td><td class="cve-value">2026-05-04</td></tr>
+<tr><td class="cve-header">Update 2.4.67 released</td><td class="cve-value">2026-05-04</td></tr>
+<tr><td class="cve-header">Affects</td><td class="cve-value"> through 2.4.66</td></tr>
+</table></dd>
 <dt><h3 id="CVE-2026-34059">low: <name name="CVE-2026-34059">Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in  ajp_parse_data()</name>
 (<a href="https://www.cve.org/CVERecord?id=CVE-2026-34059">CVE-2026-34059</a>)</h3></dt>
 <dd><p>Buffer Over-read vulnerability in Apache HTTP Server.</p><p></p><p>This issue affects Apache HTTP Server: through 2.4.66.</p><p></p><p>Users are recommended to upgrade to version 2.4.67, which fixes the issue.</p>