(httpd-site) branch asf-site updated: Automatic Site Publish by Buildbot
[email protected] Thu, 04 Jun 2026 16:37:09 +0000
| Newsgroups | gmane.comp.apache.cvs |
|---|---|
| Message-ID | <178059102954.2007810.12687511904123348019@gitbox3-he-fi.apache.org> |
This is an automated email from the ASF dual-hosted git repository.
asf-gitbox-commits pushed a commit to branch asf-site
in repository https://gitbox.apache.org/repos/asf/httpd-site.git
The following commit(s) were added to refs/heads/asf-site by this push:
new 94dd364 Automatic Site Publish by Buildbot
94dd364 is described below
commit 94dd36487d0c9045b99f119194c785934edbe6ab
Author: buildbot <[email protected]>
AuthorDate: Thu Jun 4 16:37:05 2026 +0000
Automatic Site Publish by Buildbot
---
output/security/json/CVE-2026-34032.json | 5 +++++
output/security/vulnerabilities-httpd.json | 5 +++++
output/security/vulnerabilities_24.html | 14 ++++++++++++++
3 files changed, 24 insertions(+)
diff --git a/output/security/json/CVE-2026-34032.json b/output/security/json/CVE-2026-34032.json
index 9517c74..2b4c326 100644
--- a/output/security/json/CVE-2026-34032.json
+++ b/output/security/json/CVE-2026-34032.json
@@ -101,6 +101,11 @@
"time": "2026-05-04T12:00:00.000Z",
"lang": "en",
"value": "fixed in 2.4.x by r1933343"
+ },
+ {
+ "time": "2026-05-04T00:00:00.000Z",
+ "lang": "en",
+ "value": "2.4.67 released"
}
],
"credits": [
diff --git a/output/security/vulnerabilities-httpd.json b/output/security/vulnerabilities-httpd.json
index 6d85781..38a71c7 100644
--- a/output/security/vulnerabilities-httpd.json
+++ b/output/security/vulnerabilities-httpd.json
@@ -24466,6 +24466,11 @@
"time": "2026-05-04T12:00:00.000Z",
"lang": "en",
"value": "fixed in 2.4.x by r1933343"
+ },
+ {
+ "time": "2026-05-04T00:00:00.000Z",
+ "lang": "en",
+ "value": "2.4.67 released"
}
],
"credits": [
diff --git a/output/security/vulnerabilities_24.html b/output/security/vulnerabilities_24.html
index bfb0a95..6618549 100644
--- a/output/security/vulnerabilities_24.html
+++ b/output/security/vulnerabilities_24.html
@@ -192,6 +192,20 @@ h1:hover > .headerlink, h2:hover > .headerlink, h3:hover > .headerlink, h4:hover
<tr><td class="cve-header">Update 2.4.67 released</td><td class="cve-value">2026-05-04</td></tr>
<tr><td class="cve-header">Affects</td><td class="cve-value"> through 2.4.66</td></tr>
</table></dd>
+<dt><h3 id="CVE-2026-34032">low: <name name="CVE-2026-34032">mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string)</name>
+(<a href="https://www.cve.org/CVERecord?id=CVE-2026-34032">CVE-2026-34032</a>)</h3></dt>
+<dd><p>Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server.</p><p></p><p>This issue affects Apache HTTP Server: through 2.4.66.</p><p></p><p>Users are recommended to upgrade to version 2.4.67, which fixes the issue.</p>
+<p>Acknowledgements:</p>
+<ul>
+<li>finder: Tianshuo Han (<[email protected]>)</li>
+<li>finder: Jérôme Djouder</li>
+<li>finder: Sajeeb Lohani working with TrendAI Zero Day Initiative</li>
+</ul>
+<table class="table"><tr><td class="cve-header">Report received</td><td class="cve-value">2026-03-01</td></tr>
+<tr><td class="cve-header">fixed in 2.4.x by r1933343</td><td class="cve-value">2026-05-04</td></tr>
+<tr><td class="cve-header">Update 2.4.67 released</td><td class="cve-value">2026-05-04</td></tr>
+<tr><td class="cve-header">Affects</td><td class="cve-value"> through 2.4.66</td></tr>
+</table></dd>
<dt><h3 id="CVE-2026-34059">low: <name name="CVE-2026-34059">Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data()</name>
(<a href="https://www.cve.org/CVERecord?id=CVE-2026-34059">CVE-2026-34059</a>)</h3></dt>
<dd><p>Buffer Over-read vulnerability in Apache HTTP Server.</p><p></p><p>This issue affects Apache HTTP Server: through 2.4.66.</p><p></p><p>Users are recommended to upgrade to version 2.4.67, which fixes the issue.</p>