CVE-2026-63686
- EPSS 0.33%
- Veröffentlicht 01.10.2026 16:20:14
- Zuletzt bearbeitet 05.10.2026 17:46:24
A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially...
CVE-2026-93546
- EPSS 0.34%
- Veröffentlicht 01.10.2026 16:19:32
- Zuletzt bearbeitet 05.10.2026 16:05:53
Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML n...
CVE-2026-79768
- EPSS 0.32%
- Veröffentlicht 01.10.2026 16:18:57
- Zuletzt bearbeitet 05.10.2026 17:35:50
Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir) T...
CVE-2026-73637
- EPSS 0.26%
- Veröffentlicht 01.10.2026 16:18:30
- Zuletzt bearbeitet 05.10.2026 17:39:38
Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when Auth...
CVE-2026-73636
- EPSS 0.37%
- Veröffentlicht 01.10.2026 16:17:59
- Zuletzt bearbeitet 05.10.2026 17:45:24
Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests th...
CVE-2026-63718
- EPSS 0.32%
- Veröffentlicht 01.10.2026 16:17:06
- Zuletzt bearbeitet 06.10.2026 16:46:24
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding. This issue affects Apache HTTP Server:...
CVE-2026-63292
- EPSS 0.58%
- Veröffentlicht 01.10.2026 16:11:47
- Zuletzt bearbeitet 05.10.2026 17:47:01
Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host ...
CVE-2026-63045
- EPSS 0.33%
- Veröffentlicht 01.10.2026 16:09:07
- Zuletzt bearbeitet 05.10.2026 13:15:35
Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connect...
CVE-2026-59797
- EPSS 0.39%
- Veröffentlicht 01.10.2026 16:08:31
- Zuletzt bearbeitet 05.10.2026 13:16:52
Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
CVE-2026-59685
- EPSS 0.35%
- Veröffentlicht 01.10.2026 16:07:51
- Zuletzt bearbeitet 05.10.2026 13:21:03
Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.