Red Hat Linux OS and other open source products
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Red Hat product.
RSS Feeds for Red Hat security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Red Hat products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Red Hat Sorted by Most Security Vulnerabilities since 2018
Red Hat Enterprise Linux Server1534 vulnerabilities
RedHat Enterprise Linux (RHEL) Server. Includes software bundeled with RHEL server.
Red Hat Enterprise Linux Workstation1504 vulnerabilities
RedHat Enterprise Linux (RHEL) Workstation. Includes software bundled with RHEL Workstation.
Red Hat Enterprise Linux Desktop1493 vulnerabilities
RedHat Enterprise Linux (RHEL) Desktop. Includes software bundled with RHEL desktop
Recent Red Hat Security Advisories
| Advisory | Title | Published |
|---|---|---|
| RHSA-2026:77273 | (RHSA-2026:77273) Important: Red Hat OpenShift GitOps v1.20.7 security update | October 7, 2026 |
| RHSA-2026:77269 | (RHSA-2026:77269) Important: Red Hat OpenShift GitOps v1.21.4 security update | October 7, 2026 |
| RHSA-2026:77267 | (RHSA-2026:77267) An update is now available for Red Hat OpenShift GitOps. | October 7, 2026 |
| RHSA-2026:77217 | (RHSA-2026:77217) Important: kernel security, bug fix, and enhancement update | October 7, 2026 |
| RHSA-2026:77216 | (RHSA-2026:77216) Important: kernel security, bug fix, and enhancement update | October 7, 2026 |
| RHSA-2026:77214 | (RHSA-2026:77214) Important: kernel-rt security, bug fix, and enhancement update | October 7, 2026 |
| RHSA-2026:76978 | (RHSA-2026:76978) Red Hat Hardened Images RPMs bug fix and enhancement update | October 6, 2026 |
| RHSA-2026:77004 | (RHSA-2026:77004) Red Hat Hardened Images RPMs bug fix and enhancement update | October 6, 2026 |
| RHSA-2026:77028 | (RHSA-2026:77028) Important: python3.12 security update | October 6, 2026 |
| RHSA-2026:77020 | (RHSA-2026:77020) Important: python3.12 security update | October 6, 2026 |
By the Year
In 2026 there have been 4251 vulnerabilities in Red Hat with an average score of 7.3 out of ten. Last year, in 2025 Red Hat had 1194 security vulnerabilities published. That is, 3057 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.41.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 4251 | 7.28 |
| 2025 | 1194 | 6.87 |
| 2024 | 1702 | 6.83 |
| 2023 | 1207 | 6.75 |
| 2022 | 1362 | 6.96 |
| 2021 | 1123 | 6.61 |
| 2020 | 664 | 6.39 |
| 2019 | 772 | 6.98 |
| 2018 | 760 | 7.16 |
It may take a day or so for new Red Hat vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Red Hat Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-80048 | Oct 06, 2026 |
Red Hat sssd-kcm Local DoS via Large Request HeaderA flaw was found in `sssd-kcm`. A local user or process able to connect to the `sssd-kcm` UNIX socket can exploit this vulnerability. By sending a large request length header and then stalling the connection, an attacker can cause the system to preallocate significant memory. This leads to memory exhaustion within the `sssd-kcm` responder, resulting in a Denial of Service (DoS) for affected deployments. |
|
| CVE-2026-76061 | Oct 06, 2026 |
CRI-O bind_mount_prefix Symlink Spoof leads to Host Path EscalationA flaw was found in CRI-O's `bind_mount_prefix` handling. When configured with a non-empty `bind_mount_prefix`, a malicious container or local attacker could use a Container Runtime Interface (CRI) hostPath containing an intermediate absolute symlink. This could cause the bind mount source to resolve outside the intended prefixed root, potentially leading to unauthorized access to files or privilege escalation on the host system. |
|
| CVE-2026-83550 | Oct 06, 2026 |
Go Postgres-Exporter: pprof debug endpoints exposed, info disclosure & DoSA flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows for information disclosure, potentially revealing process arguments, full goroutine stacks, and sensitive data like database connection strings or passwords from heap dumps. Additionally, repeated CPU profiling through these endpoints can lead to a denial of service. |
|
| CVE-2026-88252 | Oct 06, 2026 |
SSSD Local DoS via Responder Service File Descriptor ExhaustionA flaw was found in sssd. A local user can cause a Denial of Service (DoS) by exhausting the responder service's available file descriptors (system handles used for open connections). By opening and maintaining many concurrent connections to a responder socket while continuing to queue new connection attempts, an attacker can trigger an unthrottled retry loop. This condition leads to high CPU utilization and stalls the service, preventing legitimate identity and authentication requests from being processed. |
|
| CVE-2026-92821 | Oct 06, 2026 |
SSSD LDAP Expired-Password Bypass via Early Rule TerminationA flaw was found in SSSD. When configured to evaluate password expiration warnings before restrictive access rules in LDAP (Lightweight Directory Access Protocol) environments, an expired-password warning terminates rule evaluation early and treats the access request as successful. A remote authenticated user with an expired password using an alternative authentication method, such as SSH public key authentication, can exploit this flaw to bypass access control restrictions and gain unauthorized access to protected systems. |
|
| CVE-2026-71297 | Oct 05, 2026 |
Red Hat Maestro gRPC Broker Auth Bypass via Client CertA flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which can compromise data integrity. |
|
| CVE-2026-71299 | Oct 05, 2026 |
Maestro REST API Auth Bypass: UnAuth Writes PossibleA flaw was found in Maestro. Its REST API write endpoints were registered without proper authentication middleware. This allows a remote attacker to perform unauthorized write operations, such as creating, modifying, or deleting consumers and resource bundles. This could lead to data integrity issues or a denial of service (DoS). |
|
| CVE-2026-71298 | Oct 05, 2026 |
Unauthenticated SQLi in RedHat Maestro REST orderBy for Data ExfiltrationA flaw was found in maestro. A remote attacker could exploit a SQL injection vulnerability in the `orderBy` query parameter of its REST API list endpoints. This flaw, which does not require authentication, allows for read-only blind extraction of data from the database. |
|
| CVE-2026-94422 | Oct 02, 2026 |
xdg-dbus-proxy <0.1.9 Bypass DBus Message Filtering, Code ExecAn incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail. |
|
| CVE-2026-90440 | Oct 02, 2026 |
Apache Thrift v<0.25.0 TNonblockingServer Exception Resource Shutdown CVEUncaught exception, improper handling of exceptional conditions, improper resource shutdown vulnerability in Apache Thrift D thrift.server.nonblocking.TNonblockingServer. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
|
| CVE-2026-87117 | Oct 02, 2026 |
CVE-2026-87117: Null Pointer Deref in Apache Thrift PHP Bindings before 0.25.0NULL pointer dereference vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
|
| CVE-2026-85087 | Oct 02, 2026 |
Thrift Py Bindings CVE-2026-85087 Improper Cert Val Before 0.25.0Improper certificate validation, Return of wrong status code vulnerability in Apache Thrift python bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
|
| CVE-2026-85086 | Oct 02, 2026 |
Apache Thrift <0.25.0 Improper Cert Validation in Perl BindingsImproper certificate validation, Initialization of a resource with an insecure default vulnerability in Apache Thrift perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
|
| CVE-2026-82459 | Oct 02, 2026 |
Apache Thrift Int Underflow/OOB in 32bit THeaderTransport (0.24)Integer underflow (wrap or wraparound), Out-of-bounds write vulnerability in Apache Thrift C++ 32 bit THeaderTransport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
|
| CVE-2026-82458 | Oct 02, 2026 |
Memory Allocation DoS in Apache Thrift <0.25.0 (CVE-2026-82458)Memory allocation with excessive size value, Allocation of resources without limits or throttling vulnerability in Apache Thrift Go, netstd, OCaml, Erlang, JavaME, Rust, C++, Java, Kotlin and D language bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
|
| CVE-2026-96288 | Oct 02, 2026 |
Apache Thrift Erlang Bindings Uncontrolled Recursion (before 0.25.0)Uncontrolled Recursion, Allocation of resources without limits or throttling vulnerability in Apache Thrift Erlang bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
|
| CVE-2026-96292 | Oct 02, 2026 |
Apache Thrift Lua Binding ReDoS before 0.25.0Inefficient regular expression complexity, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
|
| CVE-2026-96294 | Oct 02, 2026 |
Apache Thrift NodeJS Bindings: Improper Exception Handling (pre-0.25.0)Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift NodeJS bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
|
| CVE-2026-96990 | Oct 02, 2026 |
Apache Thrift Erlang: Resource Exhaustion before 0.25.0Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Erlang bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
|
| CVE-2026-94644 | Oct 02, 2026 |
Apache Thrift PHP Bindings Resource Exhaustion Pre0.25.0Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
|
| CVE-2026-94645 | Oct 02, 2026 |
Apache Thrift NodeJS Bindings: Unbounded Resource Allocation (0.25.0)Improper validation of specified quantity in input, Allocation of resources without limits or throttling vulnerability in Apache Thrift nodejs bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
|
| CVE-2026-94650 | Oct 02, 2026 |
Uncontrolled Recursion in Apache Thrift c_glib Bindings before 0.25.0Uncontrolled Recursion vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
|
| CVE-2026-85483 | Oct 02, 2026 |
Uninitialized resource & wrong status in Apache Thrift c_glib (v<0.25.0)Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
|
| CVE-2026-85493 | Oct 02, 2026 |
Apache Thrift Uncontrolled Recursion in Dart/Java ME Bindings (0.24.9)Uncontrolled Recursion vulnerability in Apache Thrift Dart and Java ME bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
|
| CVE-2026-85494 | Oct 02, 2026 |
Apache Thrift 0.25.0: Improper Length Handling in BindingsImproper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python, Ruby, Erlang, Lua, Dart, JavaME, Perl, PHP and D language bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
|
| CVE-2026-91137 | Oct 02, 2026 |
Apache Thrift PHP: Improper Qty Validation / Unthrottled Resrc. (0.24.0)Improper validation of specified quantity in input, Allocation of resources without limits or throttling, Excessive Iteration vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
|
| CVE-2026-93925 | Oct 02, 2026 |
Apache Thrift: Stack overflow in THeaderProtocol before 0.25.0Stack-based buffer overflow, Incorrect bitwise shift of integer vulnerability in Apache Thrift C++ THeaderProtocol. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
|
| CVE-2026-93926 | Oct 02, 2026 |
Apache Thrift <0.25.0 Memory Leak in THeaderTransportMissing release of memory after effective lifetime, Missing release of resource after effective lifetime vulnerability in Apache Thrift THeaderTransport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
|
| CVE-2026-94633 | Oct 02, 2026 |
Memory alloc with excessive size in Apache Thrift Dart bindings before 0.25.0Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Dart bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
|
| CVE-2026-94634 | Oct 02, 2026 |
Apache Thrift Python Bindings Resource Exhaustion Before 0.25.0Allocation of resources without limits or throttling, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
|
| CVE-2026-94635 | Oct 02, 2026 |
Apache Thrift Lua Bindings 0.24 Unbounded Resource Allocation CVE-2026-94635Allocation of resources without limits or throttling, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
|
| CVE-2026-95512 | Oct 02, 2026 |
FreeType CID Font Loader Memory DoS via Repeated AllocationsA flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate. |
And others... |
| CVE-2026-86345 | Oct 01, 2026 |
389-ds-base LDAP StartTLS buffer injection allows auth bypassA flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a client application to treat a failed authentication (bind) attempt as successful. |
|
| CVE-2026-86344 | Oct 01, 2026 |
389-ds LDAP Thread Exhaustion DoS via Incomplete LDAPMessageA flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to a second worker thread before the first worker's result is flushed. The second worker blocks until nsslapd-ioblocktimeout while holding the connection mutex, preventing delivery of the completed operation's result. Repeating this across a small number of connections proportional to the configured worker-thread pool size exhausts the entire pool under default configuration, denying service to all clients (anonymous and authenticated, plaintext and TLS) for as long as the attacker maintains the connections. |
|
| CVE-2026-56098 | Oct 01, 2026 |
Katello RegistryProxiesController Auth Bypass Enables User EnumerationA flaw was found in rubygem-katello. The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registry_authorize filter. While the application identifies unauthorized requests and triggers an error response via the unauthorized method, it fails to halt the execution of the current code path (missing return statement). This failure in the control flow allows the application to proceed into subsequent business logic and database validation filters. Consequently, the application reveals its internal state through differential responses, allowing an unprivileged attacker to enumerate valid Users, Organizations, and Products across the entire instance. |
And others... |
| CVE-2026-12542 | Oct 01, 2026 |
Foreman Tail Utility OS Command Injection via Unsafe EvalA flaw was found in Foreman. The foreman-tail utility is vulnerable to OS command injection due to the unsafe use of the eval command. The script takes user-supplied arguments and incorporates them directly into a string that is then executed by eval to expand file paths. Because the input is not sanitized or quoted, a local attacker can inject shell metacharacters (e.g., ;, &, |) to execute arbitrary system commands. |
And others... |
| CVE-2026-56097 | Oct 01, 2026 |
Red Hat Katello SQLi in RegistryProxiesControllerA flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries within the RegistryProxiesController. The methods check_blob_push_org_label and get_matching_products_from_org take user-supplied labels directly from the request path and interpolate them into raw SQL fragments. This flaw is accessible to a user with only the create_personal_access_tokens permission, even if the user access is restricted, with no Organization or Location assigned. |
And others... |
| CVE-2026-12545 | Oct 01, 2026 |
Command Injection in Hammer CLI via $EDITOR InterpolationA flaw was found in rubygem-hammer_cli. A command injection vulnerability exists in Hammer CLI and the Railties (Ruby on Rails) component distributed with Satellite due to the insecure interpolation of the $EDITOR environment variable into the Ruby system() method. By passing a single interpolated string to system(), the application invokes a system shell (/bin/sh) that interprets shell metacharacters (e.g., ;, |, &). |
And others... |
| CVE-2026-96658 | Oct 01, 2026 |
Foreman RCE: SafeMode Templating BypassA flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker can append unauthorized functions to the allowed execution list, enabling them to run arbitrary commands on the hosting server. |
And others... |
| CVE-2026-96659 | Oct 01, 2026 |
Foreman Viewer Priv Info Disclosure & RCE via Template PreviewA flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under insecure system configurations where Safemode protections are disabled, the flaw may allow the user to execute arbitrary commands as the Foreman system account. |
And others... |
| CVE-2026-12544 | Oct 01, 2026 |
Foreman Vulnerable Multi-Stage Execution Enables SSTI & RCEA flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a multi-stage execution chain that allows for both Server-Side Template Injection (SSTI) and insecure deserialization. This vulnerability can lead to remote code execution, total infrastructure compromise and supply chain risk. |
And others... |
| CVE-2026-12541 | Oct 01, 2026 |
Foreman OS Command Injection via foreman-rake db:dump/db:import_dumpA flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths. |
And others... |
| CVE-2026-12540 | Oct 01, 2026 |
Foreman Rake Task Command Injection via errors:fetch_logA flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo permissions to execute this rake task can inject shell metacharacters (such as ;, ", or |) to break out of the intended command and execute arbitrary code. |
And others... |
| CVE-2026-12423 | Oct 01, 2026 |
Foreman Auth Bypass via host_verifier.rb in Satellite APIA flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. Because a host actively undergoing provisioning has an unexpired token in the database, the server's valid_host_token? method evaluates to true, granting access to the kickstart template even if the requester provides no token at all in the URL. |
And others... |
| CVE-2026-12405 | Oct 01, 2026 |
Red Hat Satellite API Job Injection via rubygem-foreman_remote_executionA flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in the Red Hat Satellite API (/api/v2/job_invocations). When a job template has the effective_user property marked as overridable: true, the application fails to properly sanitize the effective_user input provided during the API request. The exploitation does not rely on the content or logic of the Job Template/playbook itself; rather, the injection occurs during the instantiation of the job execution environment by the Satellite server. An attacker with permissions to execute job templates can inject arbitrary shell commands into this parameter, which are executed on the target infrastructure with the privileges of the execution user. |
And others... |
| CVE-2026-63686 | Oct 01, 2026 |
Apache HTTP Server: NULL pointer deref in mod_xml2enc before 2.4.69A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails. Users are recommended to upgrade to version 2.4.69, which fixes this issue. |
|
| CVE-2026-93546 | Oct 01, 2026 |
Apache HTTP Server 2.4.68 mod_dav_fs Integer Overflow via PROPPATCHInteger overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces. |
|
| CVE-2026-79768 | Oct 01, 2026 |
Apache HTTP Server 2.4.x Path Equivalence in mod_userdir (UserDir)Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. |
|
| CVE-2026-73637 | Oct 01, 2026 |
UAF in Apache HTTP Server 2.4 mod_auth_digest before 2.4.69Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue. |
|
| CVE-2026-73636 | Oct 01, 2026 |
Apache HTTP Server 2.4.x AuthDigestNonceLifetime 0 Bypass via Capture-Replay MITMAuthentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue. |