rpm package
almalinux/mod_md
pkg:rpm/almalinux/mod_md
Vulnerabilities (77)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-49975 | Hig | 7.5 | < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | Jun 8, 2026 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. | |
| CVE-2026-44631 | Cri | 9.8 | < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | Jun 8, 2026 | Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue. | |
| CVE-2026-44186 | Hig | 7.3 | < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | Jun 8, 2026 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue affects undefined: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, wh | |
| CVE-2026-44185 | Hig | 7.3 | < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | Jun 8, 2026 | Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue. | |
| CVE-2026-43951 | Med | 6.5 | < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | Jun 8, 2026 | Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. | |
| CVE-2026-42536 | Hig | 7.5 | < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | Jun 8, 2026 | Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue. | |
| CVE-2026-34356 | Hig | 7.5 | < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | Jun 8, 2026 | Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue. | |
| CVE-2026-34355 | Hig | 7.5 | < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | Jun 8, 2026 | A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue. | |
| CVE-2026-28780 | Cri | 9.8 | < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | May 5, 2026 | Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap ba | |
| CVE-2026-29168 | Hig | 7.3 | < 1:2.4.26-2.el9_8.1 | 1:2.4.26-2.el9_8.1 | May 5, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. | |
| CVE-2026-33007 | Med | 5.3 | < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | May 4, 2026 | A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration. Users are recommended to upgrade to version 2.4.67, which fixes this issue. | |
| CVE-2026-29169 | Hig | 7.5 | < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | May 4, 2026 | A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apac | |
| CVE-2026-34032 | Med | 5.3 | < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | May 4, 2026 | Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. | |
| CVE-2026-33857 | Med | 5.3 | < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | May 4, 2026 | Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. | |
| CVE-2026-34059 | Hig | 7.5 | < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | May 4, 2026 | Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. | |
| CVE-2025-58098 | Hig | 8.3 | < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | Dec 5, 2025 | Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4 | |
| CVE-2025-66200 | Med | 5.4 | < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | Dec 5, 2025 | mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4. | |
| CVE-2025-65082 | Med | 6.5 | < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | Dec 5, 2025 | Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server fr | |
| CVE-2025-55753 | Hig | 7.5 | < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | Dec 5, 2025 | An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Ap | |
| CVE-2025-53020 | Hig | 7.5 | < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2 | Jul 10, 2025 | Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue. |
- affected < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2fixed 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.
- affected < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2fixed 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2
Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
- affected < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2fixed 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue affects undefined: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, wh
- affected < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2fixed 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
- affected < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2fixed 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2
Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
- affected < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2fixed 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
- affected < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2fixed 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
- affected < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2fixed 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
- affected < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2fixed 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2
Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap ba
- affected < 1:2.4.26-2.el9_8.1fixed 1:2.4.26-2.el9_8.1
Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
- affected < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2fixed 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2
A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration. Users are recommended to upgrade to version 2.4.67, which fixes this issue.
- affected < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2fixed 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2
A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apac
- affected < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2fixed 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2
Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
- affected < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2fixed 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2
Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
- affected < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2fixed 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2
Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
- affected < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2fixed 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2
Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4
- affected < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2fixed 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2
mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.
- affected < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2fixed 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server fr
- affected < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2fixed 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2
An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Ap
- affected < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2fixed 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2
Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.
Page 1 of 4