(httpd-site) branch asf-site updated: Automatic Site Publish by Buildbot
[email protected] Mon, 08 Jun 2026 12:25:33 +0000
| Newsgroups | gmane.comp.apache.cvs |
|---|---|
| Message-ID | <178092153311.2047146.9784787265489185665@gitbox3-he-fi.apache.org> |
This is an automated email from the ASF dual-hosted git repository.
asf-gitbox-commits pushed a commit to branch asf-site
in repository https://gitbox.apache.org/repos/asf/httpd-site.git
The following commit(s) were added to refs/heads/asf-site by this push:
new 3f2cb0d Automatic Site Publish by Buildbot
3f2cb0d is described below
commit 3f2cb0d247b4fa197dd1cf3a380ce5bea85e6f42
Author: buildbot <[email protected]>
AuthorDate: Mon Jun 8 12:25:29 2026 +0000
Automatic Site Publish by Buildbot
---
output/doap.rdf | 4 +-
output/download.html | 24 +-
output/index.html | 8 +-
output/security/json/CVE-2026-29167.json | 115 ++
output/security/json/CVE-2026-29170.json | 115 ++
output/security/json/CVE-2026-34355.json | 120 +++
output/security/json/CVE-2026-34356.json | 120 +++
output/security/json/CVE-2026-42535.json | 115 ++
output/security/json/CVE-2026-42536.json | 115 ++
output/security/json/CVE-2026-43951.json | 115 ++
output/security/json/CVE-2026-44119.json | 160 +++
output/security/json/CVE-2026-44185.json | 115 ++
output/security/json/CVE-2026-44186.json | 115 ++
output/security/json/CVE-2026-44631.json | 120 +++
output/security/json/CVE-2026-48913.json | 114 ++
output/security/json/CVE-2026-49975.json | 120 +++
output/security/vulnerabilities-httpd.json | 1559 ++++++++++++++++++++++++++++
output/security/vulnerabilities_24.html | 144 +++
18 files changed, 3280 insertions(+), 18 deletions(-)
diff --git a/output/doap.rdf b/output/doap.rdf
index 1f5a1ab..e844436 100644
--- a/output/doap.rdf
+++ b/output/doap.rdf
@@ -38,8 +38,8 @@
<release>
<Version>
<name>Recommended current 2.4 release</name>
- <created>2026-05-04</created>
- <revision>2.4.67</revision>
+ <created>2026-06-08</created>
+ <revision>2.4.68</revision>
</Version>
</release>
diff --git a/output/download.html b/output/download.html
index c140864..4b43cfd 100644
--- a/output/download.html
+++ b/output/download.html
@@ -101,31 +101,31 @@ families of releases, are available from the
<a href="//httpd.apache.org/docs/current/platform/windows.html#down">a number of third party vendors</a>.</p>
<p>Stable Release - Latest Version:</p>
<ul>
-<li><a href="#apache24">2.4.67</a> (released 2026-05-04)</li>
+<li><a href="#apache24">2.4.68</a> (released 2026-06-08)</li>
</ul>
-<h1 id="apache24">Apache HTTP Server 2.4.67 (httpd): 2.4.67 is the latest available version <span>2026-05-04</span><a class="headerlink" href="#apache24" title="Permalink">¶</a></h1>
+<h1 id="apache24">Apache HTTP Server 2.4.68 (httpd): 2.4.68 is the latest available version <span>2026-06-08</span><a class="headerlink" href="#apache24" title="Permalink">¶</a></h1>
<p>The Apache HTTP Server Project is pleased to
<a href="//downloads.apache.org/httpd/Announcement2.4.txt">announce</a> the
-release of version 2.4.67 of the Apache HTTP Server ("Apache" and "httpd").
+release of version 2.4.68 of the Apache HTTP Server ("Apache" and "httpd").
This version of Apache is our latest GA release of the new generation 2.4.x
branch of Apache HTTPD and represents fifteen years of innovation by the
project, and is recommended over all previous releases!</p>
<p>For details, see the <a href="//downloads.apache.org/httpd/Announcement2.4.html">Official
Announcement</a> and
the <a href="[preferred]httpd/CHANGES_2.4">CHANGES_2.4</a> and
-<a href="[preferred]httpd/CHANGES_2.4.67">CHANGES_2.4.67</a> lists.</p>
+<a href="[preferred]httpd/CHANGES_2.4.68">CHANGES_2.4.68</a> lists.</p>
<ul>
<li>
-<p>Source: <a href="[preferred]httpd/httpd-2.4.67.tar.bz2">httpd-2.4.67.tar.bz2</a>
-[ <a href="https://downloads.apache.org/httpd/httpd-2.4.67.tar.bz2.asc">PGP</a> ] [
-<a href="https://downloads.apache.org/httpd/httpd-2.4.67.tar.bz2.sha256">SHA256</a> ] [
-<a href="https://downloads.apache.org/httpd/httpd-2.4.67.tar.bz2.sha512">SHA512</a> ]</p>
+<p>Source: <a href="[preferred]httpd/httpd-2.4.68.tar.bz2">httpd-2.4.68.tar.bz2</a>
+[ <a href="https://downloads.apache.org/httpd/httpd-2.4.68.tar.bz2.asc">PGP</a> ] [
+<a href="https://downloads.apache.org/httpd/httpd-2.4.68.tar.bz2.sha256">SHA256</a> ] [
+<a href="https://downloads.apache.org/httpd/httpd-2.4.68.tar.bz2.sha512">SHA512</a> ]</p>
</li>
<li>
-<p>Source: <a href="[preferred]httpd/httpd-2.4.67.tar.gz">httpd-2.4.67.tar.gz</a> [
-<a href="https://downloads.apache.org/httpd/httpd-2.4.67.tar.gz.asc">PGP</a> ] [
-<a href="https://downloads.apache.org/httpd/httpd-2.4.67.tar.gz.sha256">SHA256</a> ] [
-<a href="https://downloads.apache.org/httpd/httpd-2.4.67.tar.gz.sha512">SHA512</a> ]</p>
+<p>Source: <a href="[preferred]httpd/httpd-2.4.68.tar.gz">httpd-2.4.68.tar.gz</a> [
+<a href="https://downloads.apache.org/httpd/httpd-2.4.68.tar.gz.asc">PGP</a> ] [
+<a href="https://downloads.apache.org/httpd/httpd-2.4.68.tar.gz.sha256">SHA256</a> ] [
+<a href="https://downloads.apache.org/httpd/httpd-2.4.68.tar.gz.sha512">SHA512</a> ]</p>
</li>
<li>
<p><a href="[preferred]httpd/patches/">Security and official patches</a></p>
diff --git a/output/index.html b/output/index.html
index 1f7f3a9..d5e8c5c 100644
--- a/output/index.html
+++ b/output/index.html
@@ -100,16 +100,16 @@ mission-critical production infrastructure with:</p>
</ul>
<p>The Apache HTTP Server is a project of <a href="https://www.apache.org/">The Apache Software
Foundation</a>.</p>
-<h1 id="apache-httpd-2467-released-2026-05-04">Apache httpd 2.4.67 Released <span>2026-05-04</span><a class="headerlink" href="#apache-httpd-2467-released-2026-05-04" title="Permalink">¶</a></h1>
+<h1 id="apache-httpd-2468-released-2026-06-08">Apache httpd 2.4.68 Released <span>2026-06-08</span><a class="headerlink" href="#apache-httpd-2468-released-2026-06-08" title="Permalink">¶</a></h1>
<p>The Apache Software Foundation and the Apache HTTP Server Project are
pleased to
<a href="https://downloads.apache.org/httpd/Announcement2.4.html">announce</a> the
-release of version 2.4.67 of the Apache HTTP Server ("httpd").</p>
+release of version 2.4.68 of the Apache HTTP Server ("httpd").</p>
<p>This latest release from the 2.4.x stable branch represents the best available
version of Apache HTTP Server.</p>
<p>Apache HTTP Server version 2.<span>4</span>.43 or newer is required in order to operate a TLS 1.3 web server with OpenSSL 1.1.1.</p>
-<p class="centered"><a href="download.cgi#apache24">Download</a> | <a href="https://downloads.apache.org/httpd/CHANGES_2.4.67">ChangeLog for
-2.4.67</a> | <a href="https://downloads.apache.org/httpd/CHANGES_2.4">Complete ChangeLog for
+<p class="centered"><a href="download.cgi#apache24">Download</a> | <a href="https://downloads.apache.org/httpd/CHANGES_2.4.68">ChangeLog for
+2.4.68</a> | <a href="https://downloads.apache.org/httpd/CHANGES_2.4">Complete ChangeLog for
2.4</a> | <a href="docs/trunk/new_features_2_4.html">New Features in httpd
2.4</a></p>
<h1 id="apache-httpd-22-end-of-life">Apache httpd 2.2 End-of-Life<a class="headerlink" href="#apache-httpd-22-end-of-life" title="Permalink">¶</a></h1>
diff --git a/output/security/json/CVE-2026-29167.json b/output/security/json/CVE-2026-29167.json
new file mode 100644
index 0000000..1500354
--- /dev/null
+++ b/output/security/json/CVE-2026-29167.json
@@ -0,0 +1,115 @@
+{
+ "cveMetadata": {
+ "cveId": "CVE-2026-29167",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "mod_ldap per-dir use-after-free",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-416: Use After Free",
+ "lang": "en",
+ "cweId": "CWE-416",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "2.4.0",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.\n\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "<p>Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration</p><p>This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.</p><p>Users are recommended to upgrade to version 2.4.68, which fixes the issue.</p>"
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "tags": [
+ "vendor-advisory"
+ ],
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html"
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "low"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-03-02T12:00:00.000Z",
+ "lang": "en",
+ "value": "reported"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-03T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1934935"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Pavel Kohout, Aisle Research, Aisle.com",
+ "type": "finder"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+}
diff --git a/output/security/json/CVE-2026-29170.json b/output/security/json/CVE-2026-29170.json
new file mode 100644
index 0000000..b810b19
--- /dev/null
+++ b/output/security/json/CVE-2026-29170.json
@@ -0,0 +1,115 @@
+{
+ "cveMetadata": {
+ "cveId": "CVE-2026-29170",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "mod_proxy_ftp XSS",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
+ "lang": "en",
+ "cweId": "CWE-79",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "0",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration.\n\nUsers are recommended to upgrade to version 2.4.68, which fixes this issue.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration.<br><br>Users are recommended to upgrade to version 2.4.68, which fixes this issue."
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html",
+ "tags": [
+ "vendor-advisory"
+ ]
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "low"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-03-04T12:15:00.000Z",
+ "lang": "en",
+ "value": "Report received"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-04T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1934982"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Pavel Kohout, Aisle Research, Aisle.com",
+ "type": "finder"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+}
diff --git a/output/security/json/CVE-2026-34355.json b/output/security/json/CVE-2026-34355.json
new file mode 100644
index 0000000..49011c0
--- /dev/null
+++ b/output/security/json/CVE-2026-34355.json
@@ -0,0 +1,120 @@
+{
+ "cveMetadata": {
+ "cveId": "CVE-2026-34355",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "mod_proxy_html buffer overflow",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-122 Heap-based Buffer Overflow",
+ "lang": "en",
+ "cweId": "CWE-122",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "2.4.0",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend.\nUsers are recommended to upgrade to version 2.4.68, which fixes this issue.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend.<br>Users are recommended to upgrade to version 2.4.68, which fixes this issue."
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html",
+ "tags": [
+ "vendor-advisory"
+ ]
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "moderate"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-03-21T09:59:00.000Z",
+ "lang": "en",
+ "value": "Report received"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-04T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1934977"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Elhanan Haenel",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "type": "finder",
+ "value": "Junhui Lee"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+}
diff --git a/output/security/json/CVE-2026-34356.json b/output/security/json/CVE-2026-34356.json
new file mode 100644
index 0000000..da896ca
--- /dev/null
+++ b/output/security/json/CVE-2026-34356.json
@@ -0,0 +1,120 @@
+{
+ "cveMetadata": {
+ "cveId": "CVE-2026-34356",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "ProxyPassReverseCookieMap buffer overflow",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-122 Heap-based Buffer Overflow",
+ "lang": "en",
+ "cweId": "CWE-122",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "2.4.0",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie*\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.\n\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "<p>Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie*</p><p>This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.</p><p>Users are recommended to upgrade to version 2.4.68, which fixes the issue.</p>"
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html",
+ "tags": [
+ "vendor-advisory"
+ ]
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "low"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-02-23T12:00:00.000Z",
+ "lang": "en",
+ "value": "reported"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-05T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1935008"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Arkadi Vainbrand",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "type": "finder",
+ "value": "depthfirst (depthfirst.com)"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+}
diff --git a/output/security/json/CVE-2026-42535.json b/output/security/json/CVE-2026-42535.json
new file mode 100644
index 0000000..538764d
--- /dev/null
+++ b/output/security/json/CVE-2026-42535.json
@@ -0,0 +1,115 @@
+{
+ "cveMetadata": {
+ "cveId": "CVE-2026-42535",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "mod_dav_fs protected directory access",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-668 Exposure of Resource to Wrong Sphere",
+ "lang": "en",
+ "cweId": "CWE-668",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "EXTERNAL"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "0",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes.\n\nUsers are recommended to upgrade to version 2.4.68, which fixes this issue.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes.<br><br>Users are recommended to upgrade to version 2.4.68, which fixes this issue."
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "tags": [
+ "vendor-advisory"
+ ],
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html"
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "moderate"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-04-27T22:48:00.000Z",
+ "lang": "en",
+ "value": "Report received"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-05T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1935013"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Zhenpeng (Leo) Lin at depthfirst",
+ "type": "finder"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+}
diff --git a/output/security/json/CVE-2026-42536.json b/output/security/json/CVE-2026-42536.json
new file mode 100644
index 0000000..54d7d7c
--- /dev/null
+++ b/output/security/json/CVE-2026-42536.json
@@ -0,0 +1,115 @@
+{
+ "cveMetadata": {
+ "cveId": "CVE-2026-42536",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "mod_xml2enc heap overflow",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-122 Heap-based Buffer Overflow",
+ "lang": "en",
+ "cweId": "CWE-122",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "2.4.0",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.\n\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "<p>Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content</p><p>This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.</p><p>Users are recommended to upgrade to version 2.4.68, which fixes the issue.</p>"
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html",
+ "tags": [
+ "vendor-advisory"
+ ]
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "low"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-04-27T12:00:00.000Z",
+ "lang": "en",
+ "value": "reported"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-04T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1934971"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Zhenpeng (Leo) Lin at depthfirst",
+ "type": "finder"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+}
diff --git a/output/security/json/CVE-2026-43951.json b/output/security/json/CVE-2026-43951.json
new file mode 100644
index 0000000..2a226c9
--- /dev/null
+++ b/output/security/json/CVE-2026-43951.json
@@ -0,0 +1,115 @@
+{
+ "cveMetadata": {
+ "cveId": "CVE-2026-43951",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "OOB Read in `merge_response_headers` can cause crash",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-125 Out-of-bounds Read",
+ "lang": "en",
+ "cweId": "CWE-125",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "2.4.0",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages.\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "<p>Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages.</p><p>This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67."
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html",
+ "tags": [
+ "vendor-advisory"
+ ]
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "moderate"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-04-27T12:00:00.000Z",
+ "lang": "en",
+ "value": "reported"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-05T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1935006"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Zhenpeng (Leo) Lin at depthfirst",
+ "type": "finder"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+}
diff --git a/output/security/json/CVE-2026-44119.json b/output/security/json/CVE-2026-44119.json
new file mode 100644
index 0000000..ee3286a
--- /dev/null
+++ b/output/security/json/CVE-2026-44119.json
@@ -0,0 +1,160 @@
+{
+ "cveMetadata": {
+ "cveId": "CVE-2026-44119",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": "https://httpd.apache.org/",
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "escalation of privilege through expressions in .htaccess in multiple modules",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-269 Improper Privilege Management",
+ "lang": "en",
+ "cweId": "CWE-269",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "2.4.0",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.\n\nThis issue affects Apache HTTP Server: from through 2.4.67.\n\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "<p>Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.</p><p>This issue affects Apache HTTP Server: from through 2.4.67.</p><p>Users are recommended to upgrade to version 2.4.68, which fixes the issue.</p>"
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html",
+ "tags": [
+ "vendor-advisory"
+ ]
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "moderate"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-05-05T12:00:00.000Z",
+ "lang": "en",
+ "value": "reported"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-05T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1935017"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Lucian Nitescu",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "value": "as3617 (@real_as3617) at ENKI Whitehat",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "value": "Zhang San",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "value": "Martin Petrák",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "value": "joaovicdev",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "value": "Rooting | Lucas Torres",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "value": "R4mbb of KRsecurity",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "value": "gggggggga@Xiaomi ShadowBlade Security Lab",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "value": "NikKrian of H3C Security Center(h3c.com)",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "value": "lokerxx",
+ "type": "finder"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+}
diff --git a/output/security/json/CVE-2026-44185.json b/output/security/json/CVE-2026-44185.json
new file mode 100644
index 0000000..bd5731a
--- /dev/null
+++ b/output/security/json/CVE-2026-44185.json
@@ -0,0 +1,115 @@
+{
+ "cveMetadata": {
+ "cveId": "CVE-2026-44185",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "Stack Buffer Over-Read in mod_ssl OCSP `send_request`",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-126 Buffer Over-read",
+ "lang": "en",
+ "cweId": "CWE-126",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "2.4.0",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.\n\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "<p>Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server</p><p>This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.</p><p>Users are recommended to upgrade to version 2.4.68, which fixes the issue.</p>"
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html",
+ "tags": [
+ "vendor-advisory"
+ ]
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "low"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-04-27T12:00:00.000Z",
+ "lang": "en",
+ "value": "reported"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-03T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1934919"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Zhenpeng (Leo) Lin at depthfirst",
+ "type": "finder"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+}
diff --git a/output/security/json/CVE-2026-44186.json b/output/security/json/CVE-2026-44186.json
new file mode 100644
index 0000000..49f24d8
--- /dev/null
+++ b/output/security/json/CVE-2026-44186.json
@@ -0,0 +1,115 @@
+{
+ "cveMetadata": {
+ "cveId": "CVE-2026-44186",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "Loop in `proxy_ftp_handler` in mod_proxy_ftp",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')",
+ "lang": "en",
+ "cweId": "CWE-835",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "2.4.0",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server.\n\nThis issue affects undefined: from 2.4.0 through 2.4.67.\n\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "<p>Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server.</p><p>This issue affects undefined: from 2.4.0 through 2.4.67.</p><p>Users are recommended to upgrade to version 2.4.68, which fixes the issue.</p>"
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html",
+ "tags": [
+ "vendor-advisory"
+ ]
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "moderate"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-04-27T12:00:00.000Z",
+ "lang": "en",
+ "value": "reported"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-05T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1935004"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Zhenpeng (Leo) Lin at depthfirst",
+ "type": "finder"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+}
diff --git a/output/security/json/CVE-2026-44631.json b/output/security/json/CVE-2026-44631.json
new file mode 100644
index 0000000..6ee418c
--- /dev/null
+++ b/output/security/json/CVE-2026-44631.json
@@ -0,0 +1,120 @@
+{
+ "cveMetadata": {
+ "cveId": "CVE-2026-44631",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "Heap Underflow in `ap_regname` via Signed Char Overflow",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-124: Buffer Underwrite",
+ "lang": "en",
+ "cweId": "CWE-124",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "2.4.0",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration.\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.\n\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "<p>Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration.</p><p>This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.</p><p>Users are recommended to upgrade to version 2.4.68, which fixes the issue.</p>"
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html",
+ "tags": [
+ "vendor-advisory"
+ ]
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "low"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-04-27T12:00:00.000Z",
+ "lang": "en",
+ "value": "reported"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-05T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1935015"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Zhenpeng (Leo) Lin at depthfirst",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "type": "finder",
+ "value": "Bartlomiej Dmitruk"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+}
diff --git a/output/security/json/CVE-2026-48913.json b/output/security/json/CVE-2026-48913.json
new file mode 100644
index 0000000..2ba9047
--- /dev/null
+++ b/output/security/json/CVE-2026-48913.json
@@ -0,0 +1,114 @@
+{
+ "containers": {
+ "cna": {
+ "affected": [
+ {
+ "defaultStatus": "unaffected",
+ "product": "Apache HTTP Server",
+ "vendor": "Apache Software Foundation",
+ "versions": [
+ {
+ "lessThanOrEqual": "2.4.67",
+ "status": "affected",
+ "version": "2.4.55",
+ "versionType": "semver"
+ }
+ ]
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "type": "finder",
+ "value": "Sam Lovejoy, IBM X-Force Offensive Research (XOR)"
+ }
+ ],
+ "descriptions": [
+ {
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "base64": false,
+ "type": "text/html",
+ "value": "<p>Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted.</p><p>This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.</p><p><br></p>"
+ }
+ ],
+ "value": "Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted.\n\nThis issue affects Apache HTTP Server: from 2.4.55 through 2.4.67."
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "content": {
+ "text": "low"
+ },
+ "type": "Textual description of severity"
+ }
+ }
+ ],
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "cweId": "CWE-416",
+ "description": "CWE-416 Use After Free",
+ "lang": "en",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "timeline": [
+ {
+ "lang": "en",
+ "time": "2026-05-22T12:00:00.000Z",
+ "value": "reported"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-03T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1934882"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "title": "mod_http2 memory corruption when file handles exhausted",
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ },
+ "references": [
+ {
+ "tags": [
+ "vendor-advisory"
+ ],
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html"
+ }
+ ]
+ }
+ },
+ "cveMetadata": {
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "cveId": "CVE-2026-48913",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1",
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ }
+}
diff --git a/output/security/json/CVE-2026-49975.json b/output/security/json/CVE-2026-49975.json
new file mode 100644
index 0000000..e927180
--- /dev/null
+++ b/output/security/json/CVE-2026-49975.json
@@ -0,0 +1,120 @@
+{
+ "cveMetadata": {
+ "cveId": "CVE-2026-49975",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "mod_http2 denial of service",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-789 Memory Allocation with Excessive Size Value",
+ "lang": "en",
+ "cweId": "CWE-789",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "2.4.17",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests.\n\nThis issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "<p>Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests.</p><p>This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.</p><p><br></p>"
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html",
+ "tags": [
+ "vendor-advisory"
+ ]
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "moderate"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-05-26T12:00:00.000Z",
+ "lang": "en",
+ "value": "reported"
+ },
+ {
+ "time": "2026-05-27T12:00:00.000Z",
+ "lang": "en",
+ "value": "fixed upstream in mod_h2 https://github.com/icing/mod_h2/commit/35c6e405390ed361189a82acd96675401ea5947c"
+ },
+ {
+ "time": "2026-06-02T12:00:00.000Z",
+ "lang": "en",
+ "value": "fixed in 2.4.x by r1934882"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Quang Luong of Calif.IO in collaboration with OpenAI Codex",
+ "type": "finder"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+}
diff --git a/output/security/vulnerabilities-httpd.json b/output/security/vulnerabilities-httpd.json
index 38a71c7..2d618fd 100644
--- a/output/security/vulnerabilities-httpd.json
+++ b/output/security/vulnerabilities-httpd.json
@@ -2520,6 +2520,126 @@
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
},
+ {
+ "cveMetadata": {
+ "cveId": "CVE-2026-49975",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "mod_http2 denial of service",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-789 Memory Allocation with Excessive Size Value",
+ "lang": "en",
+ "cweId": "CWE-789",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "2.4.17",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests.\n\nThis issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "<p>Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests.</p><p>This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.</p><p><br></p>"
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html",
+ "tags": [
+ "vendor-advisory"
+ ]
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "moderate"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-05-26T12:00:00.000Z",
+ "lang": "en",
+ "value": "reported"
+ },
+ {
+ "time": "2026-05-27T12:00:00.000Z",
+ "lang": "en",
+ "value": "fixed upstream in mod_h2 https://github.com/icing/mod_h2/commit/35c6e405390ed361189a82acd96675401ea5947c"
+ },
+ {
+ "time": "2026-06-02T12:00:00.000Z",
+ "lang": "en",
+ "value": "fixed in 2.4.x by r1934882"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Quang Luong of Calif.IO in collaboration with OpenAI Codex",
+ "type": "finder"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+ },
{
"containers": {
"cna": {
@@ -4389,6 +4509,121 @@
}
}
},
+ {
+ "cveMetadata": {
+ "cveId": "CVE-2026-42535",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "mod_dav_fs protected directory access",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-668 Exposure of Resource to Wrong Sphere",
+ "lang": "en",
+ "cweId": "CWE-668",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "EXTERNAL"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "0",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier\u00a0allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes.\n\nUsers are recommended to upgrade to version 2.4.68, which fixes this issue.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes.<br><br>Users are recommended to upgrade to version 2.4.68, which fixes this issue."
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "tags": [
+ "vendor-advisory"
+ ],
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html"
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "moderate"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-04-27T22:48:00.000Z",
+ "lang": "en",
+ "value": "Report received"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-05T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1935013"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Zhenpeng (Leo) Lin at depthfirst",
+ "type": "finder"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+ },
{
"data_type": "CVE",
"data_format": "MITRE",
@@ -6401,6 +6636,121 @@
}
}
},
+ {
+ "cveMetadata": {
+ "cveId": "CVE-2026-44186",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "Loop in `proxy_ftp_handler` in mod_proxy_ftp",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')",
+ "lang": "en",
+ "cweId": "CWE-835",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "2.4.0",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server.\n\nThis issue affects undefined: from 2.4.0 through 2.4.67.\n\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "<p>Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server.</p><p>This issue affects undefined: from 2.4.0 through 2.4.67.</p><p>Users are recommended to upgrade to version 2.4.68, which fixes the issue.</p>"
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html",
+ "tags": [
+ "vendor-advisory"
+ ]
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "moderate"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-04-27T12:00:00.000Z",
+ "lang": "en",
+ "value": "reported"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-05T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1935004"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Zhenpeng (Leo) Lin at depthfirst",
+ "type": "finder"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+ },
{
"data_type": "CVE",
"data_format": "MITRE",
@@ -16942,6 +17292,121 @@
}
}
},
+ {
+ "cveMetadata": {
+ "cveId": "CVE-2026-44185",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "Stack Buffer Over-Read in mod_ssl OCSP `send_request`",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-126 Buffer Over-read",
+ "lang": "en",
+ "cweId": "CWE-126",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "2.4.0",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.\n\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "<p>Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server</p><p>This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.</p><p>Users are recommended to upgrade to version 2.4.68, which fixes the issue.</p>"
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html",
+ "tags": [
+ "vendor-advisory"
+ ]
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "low"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-04-27T12:00:00.000Z",
+ "lang": "en",
+ "value": "reported"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-03T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1934919"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Zhenpeng (Leo) Lin at depthfirst",
+ "type": "finder"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+ },
{
"containers": {
"cna": {
@@ -17770,6 +18235,126 @@
}
}
},
+ {
+ "cveMetadata": {
+ "cveId": "CVE-2026-44631",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "Heap Underflow in `ap_regname` via Signed Char Overflow",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-124: Buffer Underwrite",
+ "lang": "en",
+ "cweId": "CWE-124",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "2.4.0",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration.\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.\n\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "<p>Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration.</p><p>This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.</p><p>Users are recommended to upgrade to version 2.4.68, which fixes the issue.</p>"
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html",
+ "tags": [
+ "vendor-advisory"
+ ]
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "low"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-04-27T12:00:00.000Z",
+ "lang": "en",
+ "value": "reported"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-05T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1935015"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Zhenpeng (Leo) Lin at depthfirst",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "type": "finder",
+ "value": "Bartlomiej Dmitruk"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+ },
{
"data_type": "CVE",
"data_format": "MITRE",
@@ -20406,6 +20991,121 @@
}
}
},
+ {
+ "cveMetadata": {
+ "cveId": "CVE-2026-29167",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "mod_ldap per-dir use-after-free",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-416: Use After Free",
+ "lang": "en",
+ "cweId": "CWE-416",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "2.4.0",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.\n\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "<p>Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration</p><p>This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.</p><p>Users are recommended to upgrade to version 2.4.68, which fixes the issue.</p>"
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "tags": [
+ "vendor-advisory"
+ ],
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html"
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "low"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-03-02T12:00:00.000Z",
+ "lang": "en",
+ "value": "reported"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-03T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1934935"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Pavel Kohout, Aisle Research, Aisle.com",
+ "type": "finder"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+ },
{
"cveMetadata": {
"cveId": "CVE-2006-20001",
@@ -22700,6 +23400,166 @@
}
}
},
+ {
+ "cveMetadata": {
+ "cveId": "CVE-2026-44119",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": "https://httpd.apache.org/",
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "escalation of privilege through expressions in .htaccess in multiple modules",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-269 Improper Privilege Management",
+ "lang": "en",
+ "cweId": "CWE-269",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "2.4.0",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.\n\nThis issue affects Apache HTTP Server: from through 2.4.67.\n\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "<p>Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.</p><p>This issue affects Apache HTTP Server: from through 2.4.67.</p><p>Users are recommended to upgrade to version 2.4.68, which fixes the issue.</p>"
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html",
+ "tags": [
+ "vendor-advisory"
+ ]
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "moderate"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-05-05T12:00:00.000Z",
+ "lang": "en",
+ "value": "reported"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-05T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1935017"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Lucian Nitescu",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "value": "as3617 (@real_as3617) at ENKI Whitehat",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "value": "Zhang San",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "value": "Martin Petr\u00e1k",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "value": "joaovicdev",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "value": "Rooting | Lucas Torres",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "value": "R4mbb of KRsecurity",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "value": "gggggggga@Xiaomi ShadowBlade Security Lab",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "value": "NikKrian of H3C Security Center(h3c.com)",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "value": "lokerxx",
+ "type": "finder"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+ },
{
"data_type": "CVE",
"data_format": "MITRE",
@@ -22822,6 +23682,121 @@
}
]
},
+ {
+ "cveMetadata": {
+ "cveId": "CVE-2026-43951",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "OOB Read in `merge_response_headers` can cause crash",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-125 Out-of-bounds Read",
+ "lang": "en",
+ "cweId": "CWE-125",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "2.4.0",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages.\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "<p>Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages.</p><p>This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67."
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html",
+ "tags": [
+ "vendor-advisory"
+ ]
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "moderate"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-04-27T12:00:00.000Z",
+ "lang": "en",
+ "value": "reported"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-05T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1935006"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Zhenpeng (Leo) Lin at depthfirst",
+ "type": "finder"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+ },
{
"data_type": "CVE",
"data_format": "MITRE",
@@ -24498,6 +25473,240 @@
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
},
+ {
+ "containers": {
+ "cna": {
+ "affected": [
+ {
+ "defaultStatus": "unaffected",
+ "product": "Apache HTTP Server",
+ "vendor": "Apache Software Foundation",
+ "versions": [
+ {
+ "lessThanOrEqual": "2.4.67",
+ "status": "affected",
+ "version": "2.4.55",
+ "versionType": "semver"
+ }
+ ]
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "type": "finder",
+ "value": "Sam Lovejoy, IBM X-Force Offensive Research (XOR)"
+ }
+ ],
+ "descriptions": [
+ {
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "base64": false,
+ "type": "text/html",
+ "value": "<p>Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted.</p><p>This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.</p><p><br></p>"
+ }
+ ],
+ "value": "Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted.\n\nThis issue affects Apache HTTP Server: from 2.4.55 through 2.4.67."
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "content": {
+ "text": "low"
+ },
+ "type": "Textual description of severity"
+ }
+ }
+ ],
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "cweId": "CWE-416",
+ "description": "CWE-416 Use After Free",
+ "lang": "en",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "timeline": [
+ {
+ "lang": "en",
+ "time": "2026-05-22T12:00:00.000Z",
+ "value": "reported"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-03T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1934882"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "title": "mod_http2 memory corruption when file handles exhausted",
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ },
+ "references": [
+ {
+ "tags": [
+ "vendor-advisory"
+ ],
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html"
+ }
+ ]
+ }
+ },
+ "cveMetadata": {
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "cveId": "CVE-2026-48913",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1",
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ }
+ },
+ {
+ "cveMetadata": {
+ "cveId": "CVE-2026-34356",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "ProxyPassReverseCookieMap buffer overflow",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-122 Heap-based Buffer Overflow",
+ "lang": "en",
+ "cweId": "CWE-122",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "2.4.0",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie*\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.\n\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "<p>Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie*</p><p>This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.</p><p>Users are recommended to upgrade to version 2.4.68, which fixes the issue.</p>"
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html",
+ "tags": [
+ "vendor-advisory"
+ ]
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "low"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-02-23T12:00:00.000Z",
+ "lang": "en",
+ "value": "reported"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-05T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1935008"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Arkadi Vainbrand",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "type": "finder",
+ "value": "depthfirst (depthfirst.com)"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+ },
{
"data_type": "CVE",
"data_format": "MITRE",
@@ -24959,6 +26168,121 @@
}
}
},
+ {
+ "cveMetadata": {
+ "cveId": "CVE-2026-42536",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "mod_xml2enc heap overflow",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-122 Heap-based Buffer Overflow",
+ "lang": "en",
+ "cweId": "CWE-122",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "2.4.0",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "Heap-based Buffer Overflow vulnerability in Apache HTTP Server with\u00a0mod_xml2enc, xml2StartParse, and untrusted content\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.\n\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "<p>Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content</p><p>This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.</p><p>Users are recommended to upgrade to version 2.4.68, which fixes the issue.</p>"
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html",
+ "tags": [
+ "vendor-advisory"
+ ]
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "low"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-04-27T12:00:00.000Z",
+ "lang": "en",
+ "value": "reported"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-04T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1934971"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Zhenpeng (Leo) Lin at depthfirst",
+ "type": "finder"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+ },
{
"data_type": "CVE",
"data_format": "MITRE",
@@ -38521,6 +39845,126 @@
}
}
},
+ {
+ "cveMetadata": {
+ "cveId": "CVE-2026-34355",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "mod_proxy_html buffer overflow",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-122 Heap-based Buffer Overflow",
+ "lang": "en",
+ "cweId": "CWE-122",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "2.4.0",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend.\nUsers are recommended to upgrade to version 2.4.68, which fixes this issue.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend.<br>Users are recommended to upgrade to version 2.4.68, which fixes this issue."
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html",
+ "tags": [
+ "vendor-advisory"
+ ]
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "moderate"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-03-21T09:59:00.000Z",
+ "lang": "en",
+ "value": "Report received"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-04T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1934977"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Elhanan Haenel",
+ "type": "finder"
+ },
+ {
+ "lang": "en",
+ "type": "finder",
+ "value": "Junhui Lee"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+ },
{
"data_type": "CVE",
"data_format": "MITRE",
@@ -39118,6 +40562,121 @@
}
}
},
+ {
+ "cveMetadata": {
+ "cveId": "CVE-2026-29170",
+ "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
+ "serial": 1,
+ "state": "PUBLISHED"
+ },
+ "CNA_private": {
+ "emailed": null,
+ "projecturl": null,
+ "owner": "httpd",
+ "userslist": "[email protected]",
+ "state": "DRAFT",
+ "todo": [],
+ "type": "unsure"
+ },
+ "containers": {
+ "cna": {
+ "providerMetadata": {
+ "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09"
+ },
+ "title": "mod_proxy_ftp XSS",
+ "problemTypes": [
+ {
+ "descriptions": [
+ {
+ "description": "CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
+ "lang": "en",
+ "cweId": "CWE-79",
+ "type": "CWE"
+ }
+ ]
+ }
+ ],
+ "source": {
+ "discovery": "UNKNOWN"
+ },
+ "affected": [
+ {
+ "vendor": "Apache Software Foundation",
+ "product": "Apache HTTP Server",
+ "versions": [
+ {
+ "status": "affected",
+ "version": "0",
+ "lessThanOrEqual": "2.4.67",
+ "versionType": "semver"
+ }
+ ],
+ "defaultStatus": "unaffected"
+ }
+ ],
+ "descriptions": [
+ {
+ "value": "A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration.\n\nUsers are recommended to upgrade to version 2.4.68, which fixes this issue.",
+ "lang": "en",
+ "supportingMedia": [
+ {
+ "type": "text/html",
+ "base64": false,
+ "value": "A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration.<br><br>Users are recommended to upgrade to version 2.4.68, which fixes this issue."
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "url": "https://httpd.apache.org/security/vulnerabilities_24.html",
+ "tags": [
+ "vendor-advisory"
+ ]
+ }
+ ],
+ "metrics": [
+ {
+ "other": {
+ "type": "Textual description of severity",
+ "content": {
+ "text": "low"
+ }
+ }
+ }
+ ],
+ "timeline": [
+ {
+ "time": "2026-03-04T12:15:00.000Z",
+ "lang": "en",
+ "value": "Report received"
+ },
+ {
+ "lang": "en",
+ "time": "2026-06-04T12:00:00.000Z",
+ "value": "fixed in 2.4.x by r1934982"
+ },
+ {
+ "lang": "eng",
+ "time": "2026-06-08T12:00:00.000Z",
+ "value": "2.4.68 released"
+ }
+ ],
+ "credits": [
+ {
+ "lang": "en",
+ "value": "Pavel Kohout, Aisle Research, Aisle.com",
+ "type": "finder"
+ }
+ ],
+ "x_generator": {
+ "engine": "Vulnogram 0.2.0"
+ }
+ }
+ },
+ "dataType": "CVE_RECORD",
+ "dataVersion": "5.1"
+ },
{
"data_type": "CVE",
"data_format": "MITRE",
diff --git a/output/security/vulnerabilities_24.html b/output/security/vulnerabilities_24.html
index 6618549..651875c 100644
--- a/output/security/vulnerabilities_24.html
+++ b/output/security/vulnerabilities_24.html
@@ -92,6 +92,150 @@ h1:hover > .headerlink, h2:hover > .headerlink, h3:hover > .headerlink, h4:hover
<p>Please note that if a vulnerability is shown below as being fixed in a "-dev" release then this means that a fix has been applied to the development source tree and will be part of an upcoming full release.</p>
<p>Please send comments or corrections for these vulnerabilities to the <a href="/security_report.html">Security Team</a>.</p> <br/>
<p><em>The initial GA release, Apache httpd 2.4.1, includes fixes for all vulnerabilities which have been resolved in Apache httpd 2.2.22 and all older releases. Consult the <a href="vulnerabilities_22.html">Apache httpd 2.2 vulnerabilities list</a> for more information.</em></p><br/>
+<h1 id="2.4.68">Fixed in Apache HTTP Server 2.4.68</h1><dl>
+<dt><h3 id="CVE-2026-29167">low: <name name="CVE-2026-29167">mod_ldap per-dir use-after-free</name>
+(<a href="https://www.cve.org/CVERecord?id=CVE-2026-29167">CVE-2026-29167</a>)</h3></dt>
+<dd><p>Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration</p><p></p><p>This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.</p><p></p><p>Users are recommended to upgrade to version 2.4.68, which fixes the issue.</p>
+<p>Acknowledgements: finder: Pavel Kohout, Aisle Research, Aisle.com</p>
+<table class="table"><tr><td class="cve-header">Reported to security team</td><td class="cve-value">2026-03-02</td></tr>
+<tr><td class="cve-header">fixed in 2.4.x by r1934935</td><td class="cve-value">2026-06-03</td></tr>
+<tr><td class="cve-header">Update 2.4.68 released</td><td class="cve-value">2026-06-08</td></tr>
+<tr><td class="cve-header">Affects</td><td class="cve-value">2.4.0 through 2.4.67</td></tr>
+</table></dd>
+<dt><h3 id="CVE-2026-29170">low: <name name="CVE-2026-29170">mod_proxy_ftp XSS</name>
+(<a href="https://www.cve.org/CVERecord?id=CVE-2026-29170">CVE-2026-29170</a>)</h3></dt>
+<dd><p>A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration.</p><p></p><p>Users are recommended to upgrade to version 2.4.68, which fixes this issue.</p>
+<p>Acknowledgements: finder: Pavel Kohout, Aisle Research, Aisle.com</p>
+<table class="table"><tr><td class="cve-header">Report received</td><td class="cve-value">2026-03-04</td></tr>
+<tr><td class="cve-header">fixed in 2.4.x by r1934982</td><td class="cve-value">2026-06-04</td></tr>
+<tr><td class="cve-header">Update 2.4.68 released</td><td class="cve-value">2026-06-08</td></tr>
+<tr><td class="cve-header">Affects</td><td class="cve-value"> through 2.4.67</td></tr>
+</table></dd>
+<dt><h3 id="CVE-2026-34355">moderate: <name name="CVE-2026-34355">mod_proxy_html buffer overflow</name>
+(<a href="https://www.cve.org/CVERecord?id=CVE-2026-34355">CVE-2026-34355</a>)</h3></dt>
+<dd><p>A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend.</p><p>Users are recommended to upgrade to version 2.4.68, which fixes this issue.</p>
+<p>Acknowledgements:</p>
+<ul>
+<li>finder: Elhanan Haenel</li>
+<li>finder: Junhui Lee</li>
+</ul>
+<table class="table"><tr><td class="cve-header">Report received</td><td class="cve-value">2026-03-21</td></tr>
+<tr><td class="cve-header">fixed in 2.4.x by r1934977</td><td class="cve-value">2026-06-04</td></tr>
+<tr><td class="cve-header">Update 2.4.68 released</td><td class="cve-value">2026-06-08</td></tr>
+<tr><td class="cve-header">Affects</td><td class="cve-value">2.4.0 through 2.4.67</td></tr>
+</table></dd>
+<dt><h3 id="CVE-2026-34356">low: <name name="CVE-2026-34356">ProxyPassReverseCookieMap buffer overflow</name>
+(<a href="https://www.cve.org/CVERecord?id=CVE-2026-34356">CVE-2026-34356</a>)</h3></dt>
+<dd><p>Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie*</p><p></p><p>This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.</p><p></p><p>Users are recommended to upgrade to version 2.4.68, which fixes the issue.</p>
+<p>Acknowledgements:</p>
+<ul>
+<li>finder: Arkadi Vainbrand</li>
+<li>finder: depthfirst (depthfirst.com)</li>
+</ul>
+<table class="table"><tr><td class="cve-header">Reported to security team</td><td class="cve-value">2026-02-23</td></tr>
+<tr><td class="cve-header">fixed in 2.4.x by r1935008</td><td class="cve-value">2026-06-05</td></tr>
+<tr><td class="cve-header">Update 2.4.68 released</td><td class="cve-value">2026-06-08</td></tr>
+<tr><td class="cve-header">Affects</td><td class="cve-value">2.4.0 through 2.4.67</td></tr>
+</table></dd>
+<dt><h3 id="CVE-2026-42535">moderate: <name name="CVE-2026-42535">mod_dav_fs protected directory access</name>
+(<a href="https://www.cve.org/CVERecord?id=CVE-2026-42535">CVE-2026-42535</a>)</h3></dt>
+<dd><p>A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes.</p><p></p><p>Users are recommended to upgrade to version 2.4.68, which fixes this issue.</p>
+<p>Acknowledgements: finder: Zhenpeng (Leo) Lin at depthfirst</p>
+<table class="table"><tr><td class="cve-header">Report received</td><td class="cve-value">2026-04-27</td></tr>
+<tr><td class="cve-header">fixed in 2.4.x by r1935013</td><td class="cve-value">2026-06-05</td></tr>
+<tr><td class="cve-header">Update 2.4.68 released</td><td class="cve-value">2026-06-08</td></tr>
+<tr><td class="cve-header">Affects</td><td class="cve-value"> through 2.4.67</td></tr>
+</table></dd>
+<dt><h3 id="CVE-2026-42536">low: <name name="CVE-2026-42536">mod_xml2enc heap overflow</name>
+(<a href="https://www.cve.org/CVERecord?id=CVE-2026-42536">CVE-2026-42536</a>)</h3></dt>
+<dd><p>Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content</p><p></p><p>This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.</p><p></p><p>Users are recommended to upgrade to version 2.4.68, which fixes the issue.</p>
+<p>Acknowledgements: finder: Zhenpeng (Leo) Lin at depthfirst</p>
+<table class="table"><tr><td class="cve-header">Reported to security team</td><td class="cve-value">2026-04-27</td></tr>
+<tr><td class="cve-header">fixed in 2.4.x by r1934971</td><td class="cve-value">2026-06-04</td></tr>
+<tr><td class="cve-header">Update 2.4.68 released</td><td class="cve-value">2026-06-08</td></tr>
+<tr><td class="cve-header">Affects</td><td class="cve-value">2.4.0 through 2.4.67</td></tr>
+</table></dd>
+<dt><h3 id="CVE-2026-43951">moderate: <name name="CVE-2026-43951">OOB Read in `merge_response_headers` can cause crash</name>
+(<a href="https://www.cve.org/CVERecord?id=CVE-2026-43951">CVE-2026-43951</a>)</h3></dt>
+<dd><p>Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages.</p><p></p><p>This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.</p>
+<p>Acknowledgements: finder: Zhenpeng (Leo) Lin at depthfirst</p>
+<table class="table"><tr><td class="cve-header">Reported to security team</td><td class="cve-value">2026-04-27</td></tr>
+<tr><td class="cve-header">fixed in 2.4.x by r1935006</td><td class="cve-value">2026-06-05</td></tr>
+<tr><td class="cve-header">Update 2.4.68 released</td><td class="cve-value">2026-06-08</td></tr>
+<tr><td class="cve-header">Affects</td><td class="cve-value">2.4.0 through 2.4.67</td></tr>
+</table></dd>
+<dt><h3 id="CVE-2026-44119">moderate: <name name="CVE-2026-44119">escalation of privilege through expressions in .htaccess in multiple modules</name>
+(<a href="https://www.cve.org/CVERecord?id=CVE-2026-44119">CVE-2026-44119</a>)</h3></dt>
+<dd><p>Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.</p><p></p><p>This issue affects Apache HTTP Server: from through 2.4.67.</p><p></p><p>Users are recommended to upgrade to version 2.4.68, which fixes the issue.</p>
+<p>Acknowledgements:</p>
+<ul>
+<li>finder: Lucian Nitescu</li>
+<li>finder: as3617 (@real_as3617) at ENKI Whitehat</li>
+<li>finder: Zhang San</li>
+<li>finder: Martin Petrák</li>
+<li>finder: joaovicdev</li>
+<li>finder: Rooting | Lucas Torres</li>
+<li>finder: R4mbb of KRsecurity</li>
+<li>finder: gggggggga@Xiaomi ShadowBlade Security Lab</li>
+<li>finder: NikKrian of H3C Security Center(h3c.com)</li>
+<li>finder: lokerxx</li>
+</ul>
+<table class="table"><tr><td class="cve-header">Reported to security team</td><td class="cve-value">2026-05-05</td></tr>
+<tr><td class="cve-header">fixed in 2.4.x by r1935017</td><td class="cve-value">2026-06-05</td></tr>
+<tr><td class="cve-header">Update 2.4.68 released</td><td class="cve-value">2026-06-08</td></tr>
+<tr><td class="cve-header">Affects</td><td class="cve-value">2.4.0 through 2.4.67</td></tr>
+</table></dd>
+<dt><h3 id="CVE-2026-44185">low: <name name="CVE-2026-44185">Stack Buffer Over-Read in mod_ssl OCSP `send_request`</name>
+(<a href="https://www.cve.org/CVERecord?id=CVE-2026-44185">CVE-2026-44185</a>)</h3></dt>
+<dd><p>Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server</p><p></p><p>This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.</p><p></p><p>Users are recommended to upgrade to version 2.4.68, which fixes the issue.</p>
+<p>Acknowledgements: finder: Zhenpeng (Leo) Lin at depthfirst</p>
+<table class="table"><tr><td class="cve-header">Reported to security team</td><td class="cve-value">2026-04-27</td></tr>
+<tr><td class="cve-header">fixed in 2.4.x by r1934919</td><td class="cve-value">2026-06-03</td></tr>
+<tr><td class="cve-header">Update 2.4.68 released</td><td class="cve-value">2026-06-08</td></tr>
+<tr><td class="cve-header">Affects</td><td class="cve-value">2.4.0 through 2.4.67</td></tr>
+</table></dd>
+<dt><h3 id="CVE-2026-44186">moderate: <name name="CVE-2026-44186">Loop in `proxy_ftp_handler` in mod_proxy_ftp</name>
+(<a href="https://www.cve.org/CVERecord?id=CVE-2026-44186">CVE-2026-44186</a>)</h3></dt>
+<dd><p>Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server.</p><p></p><p>This issue affects undefined: from 2.4.0 through 2.4.67.</p><p></p><p>Users are recommended to upgrade to version 2.4.68, which fixes the issue.</p>
+<p>Acknowledgements: finder: Zhenpeng (Leo) Lin at depthfirst</p>
+<table class="table"><tr><td class="cve-header">Reported to security team</td><td class="cve-value">2026-04-27</td></tr>
+<tr><td class="cve-header">fixed in 2.4.x by r1935004</td><td class="cve-value">2026-06-05</td></tr>
+<tr><td class="cve-header">Update 2.4.68 released</td><td class="cve-value">2026-06-08</td></tr>
+<tr><td class="cve-header">Affects</td><td class="cve-value">2.4.0 through 2.4.67</td></tr>
+</table></dd>
+<dt><h3 id="CVE-2026-44631">low: <name name="CVE-2026-44631">Heap Underflow in `ap_regname` via Signed Char Overflow</name>
+(<a href="https://www.cve.org/CVERecord?id=CVE-2026-44631">CVE-2026-44631</a>)</h3></dt>
+<dd><p>Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration.</p><p></p><p>This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.</p><p></p><p>Users are recommended to upgrade to version 2.4.68, which fixes the issue.</p>
+<p>Acknowledgements:</p>
+<ul>
+<li>finder: Zhenpeng (Leo) Lin at depthfirst</li>
+<li>finder: Bartlomiej Dmitruk</li>
+</ul>
+<table class="table"><tr><td class="cve-header">Reported to security team</td><td class="cve-value">2026-04-27</td></tr>
+<tr><td class="cve-header">fixed in 2.4.x by r1935015</td><td class="cve-value">2026-06-05</td></tr>
+<tr><td class="cve-header">Update 2.4.68 released</td><td class="cve-value">2026-06-08</td></tr>
+<tr><td class="cve-header">Affects</td><td class="cve-value">2.4.0 through 2.4.67</td></tr>
+</table></dd>
+<dt><h3 id="CVE-2026-48913">low: <name name="CVE-2026-48913">mod_http2 memory corruption when file handles exhausted</name>
+(<a href="https://www.cve.org/CVERecord?id=CVE-2026-48913">CVE-2026-48913</a>)</h3></dt>
+<dd><p>Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted.</p><p></p><p>This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.</p>
+<p>Acknowledgements: finder: Sam Lovejoy, IBM X-Force Offensive Research (XOR)</p>
+<table class="table"><tr><td class="cve-header">Reported to security team</td><td class="cve-value">2026-05-22</td></tr>
+<tr><td class="cve-header">fixed in 2.4.x by r1934882</td><td class="cve-value">2026-06-03</td></tr>
+<tr><td class="cve-header">Update 2.4.68 released</td><td class="cve-value">2026-06-08</td></tr>
+<tr><td class="cve-header">Affects</td><td class="cve-value">2.4.55 through 2.4.67</td></tr>
+</table></dd>
+<dt><h3 id="CVE-2026-49975">moderate: <name name="CVE-2026-49975">mod_http2 denial of service</name>
+(<a href="https://www.cve.org/CVERecord?id=CVE-2026-49975">CVE-2026-49975</a>)</h3></dt>
+<dd><p>Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests.</p><p></p><p>This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.</p>
+<p>Acknowledgements: finder: Quang Luong of Calif.IO in collaboration with OpenAI Codex</p>
+<table class="table"><tr><td class="cve-header">Reported to security team</td><td class="cve-value">2026-05-26</td></tr>
+<tr><td class="cve-header">fixed upstream in mod_h2 https://github.com/icing/mod_h2/commit/35c6e405390ed361189a82acd96675401ea5947c</td><td class="cve-value">2026-05-27</td></tr>
+<tr><td class="cve-header">fixed in 2.4.x by r1934882</td><td class="cve-value">2026-06-02</td></tr>
+<tr><td class="cve-header">Update 2.4.68 released</td><td class="cve-value">2026-06-08</td></tr>
+<tr><td class="cve-header">Affects</td><td class="cve-value">2.4.17 through 2.4.67</td></tr>
+</table></dd>
+</dl>
<h1 id="2.4.67">Fixed in Apache HTTP Server 2.4.67</h1><dl>
<dt><h3 id="CVE-2026-23918">important: <name name="CVE-2026-23918">Apache HTTP Server: http2: double free and possible RCE on early reset</name>
(<a href="https://www.cve.org/CVERecord?id=CVE-2026-23918">CVE-2026-23918</a>)</h3></dt>