VYPR

BusyBox httpd

by Red Hat

CVEs (2)

  • CVE-2026-88837MedSep 23, 2026
    risk 0.42cvss 6.5epss 0.00

    BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check.

  • CVE-2026-88831MedSep 23, 2026
    risk 0.34cvss 5.3epss 0.00

    BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients.