Red Hat Red Hat Linux OS and other open source products

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Red Hat product.

RSS Feeds for Red Hat security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Red Hat products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Red Hat Sorted by Most Security Vulnerabilities since 2018

Red Hat Enterprise Linux (RHEL)2853 vulnerabilities

Red Hat Enterprise Linux Server1534 vulnerabilities
RedHat Enterprise Linux (RHEL) Server. Includes software bundeled with RHEL server.

Red Hat Enterprise Linux Workstation1504 vulnerabilities
RedHat Enterprise Linux (RHEL) Workstation. Includes software bundled with RHEL Workstation.

Red Hat Enterprise Linux Desktop1493 vulnerabilities
RedHat Enterprise Linux (RHEL) Desktop. Includes software bundled with RHEL desktop

Red Hat Enterprise Linux Eus1188 vulnerabilities

Red Hat Openshift658 vulnerabilities

Red Hat Rhel Eus653 vulnerabilities

Red Hat Rhel E4s550 vulnerabilities

Red Hat Rhel Tus480 vulnerabilities

Red Hat Rhel Aus467 vulnerabilities

Red Hat Satellite388 vulnerabilities

Red Hat Rhel Eus Long Life384 vulnerabilities

Red Hat Openshift Ai364 vulnerabilities

Red Hat Rhel Els362 vulnerabilities

Red Hat Hummingbird335 vulnerabilities

Red Hat Openstack288 vulnerabilities

Red Hat Build Keycloak267 vulnerabilities

Red Hat Jbosseapxp248 vulnerabilities

Red Hat Jboss Fuse241 vulnerabilities

Red Hat Single Sign On236 vulnerabilities

Red Hat Jboss Data Grid216 vulnerabilities

Red Hat Rhivos199 vulnerabilities

Red Hat Openshift Devspaces161 vulnerabilities

Red Hat Acm159 vulnerabilities

Red Hat Quay158 vulnerabilities

Red Hat Enterprise Linux Ai157 vulnerabilities

Red Hat Rhdh128 vulnerabilities

Red Hat Discovery125 vulnerabilities

Red Hat Software Collections123 vulnerabilities

Red Hat Keycloak123 vulnerabilities

Red Hat Cryostat121 vulnerabilities

Red Hat Ai Inference Server115 vulnerabilities

Red Hat Virtualization115 vulnerabilities

Red Hat Camel Spring Boot111 vulnerabilities

Red Hat Kafka104 vulnerabilities

Red Hat Rhui99 vulnerabilities

Red Hat Apache Camel Hawtio99 vulnerabilities

Red Hat Ceph Storage99 vulnerabilities

Red Hat Multicluster Engine96 vulnerabilities

Red Hat Openshift Pipelines95 vulnerabilities

Red Hat Single Sign On95 vulnerabilities

Red Hat Amq Broker94 vulnerabilities

Red Hat Logging92 vulnerabilities

Red Hat Quarkus89 vulnerabilities

Red Hat Amq Streams86 vulnerabilities

Red Hat Service Mesh84 vulnerabilities

Red Hat Camel Quarkus79 vulnerabilities

Red Hat Ansible Portal77 vulnerabilities

Red Hat Apicurio Registry77 vulnerabilities

Red Hat Serverless76 vulnerabilities

Red Hat Openshift Lightspeed75 vulnerabilities

Red Hat Http Server74 vulnerabilities

Red Hat Ansible Tower69 vulnerabilities

Red Hat Cert Manager68 vulnerabilities

Red Hat Satellite Capsule68 vulnerabilities

Red Hat Openshift Gitops68 vulnerabilities

Red Hat 3scale Amp63 vulnerabilities

Red Hat Podman Desktop58 vulnerabilities

Red Hat Rhmt56 vulnerabilities

Red Hat Debezium55 vulnerabilities

Red Hat Directory Server55 vulnerabilities

Red Hat Libvirt55 vulnerabilities

Red Hat Satellite Utils54 vulnerabilities

Red Hat Multicluster Globalhub54 vulnerabilities

Red Hat Service Registry54 vulnerabilities

Red Hat Virtualization Host53 vulnerabilities

Red Hat Network Observ Optr51 vulnerabilities

Red Hat Jboss Core Services48 vulnerabilities

Red Hat Insights Proxy44 vulnerabilities

Recent Red Hat Security Advisories

Advisory Title Published
RHSA-2026:74870 (RHSA-2026:74870) Red Hat Hardened Images RPMs bug fix and enhancement update October 3, 2026
RHSA-2026:75119 (RHSA-2026:75119) Red Hat Hardened Images RPMs bug fix and enhancement update October 3, 2026
RHSA-2026:74974 (RHSA-2026:74974) Important: kernel security update October 2, 2026
RHSA-2026:74972 (RHSA-2026:74972) Red Hat Hardened Images RPMs bug fix and enhancement update October 2, 2026
RHSA-2026:74952 (RHSA-2026:74952) Red Hat Hardened Images RPMs Security Update October 2, 2026
RHSA-2026:74950 (RHSA-2026:74950) Red Hat Hardened Images RPMs Security Update October 2, 2026
RHSA-2026:74861 (RHSA-2026:74861) Red Hat Hardened Images RPMs Security Update October 2, 2026
RHSA-2026:74922 (RHSA-2026:74922) Red Hat Hardened Images RPMs bug fix and enhancement update October 2, 2026
RHSA-2026:74369 (RHSA-2026:74369) Red Hat Hardened Images RPMs bug fix and enhancement update October 2, 2026
RHSA-2026:74948 (RHSA-2026:74948) Red Hat Hardened Images RPMs Security Update October 2, 2026

By the Year

In 2026 there have been 4174 vulnerabilities in Red Hat with an average score of 7.3 out of ten. Last year, in 2025 Red Hat had 1190 security vulnerabilities published. That is, 2984 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.39.




Year Vulnerabilities Average Score
2026 4174 7.25
2025 1190 6.87
2024 1702 6.83
2023 1207 6.75
2022 1362 6.96
2021 1123 6.61
2020 664 6.39
2019 772 6.98
2018 760 7.16

It may take a day or so for new Red Hat vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Red Hat Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-94422 Oct 02, 2026
xdg-dbus-proxy <0.1.9 Bypass DBus Message Filtering, Code Exec An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail.
Enterprise Linux (RHEL)
CVE-2026-90440 Oct 02, 2026
Apache Thrift v<0.25.0 TNonblockingServer Exception Resource Shutdown CVE Uncaught exception, improper handling of exceptional conditions, improper resource shutdown vulnerability in Apache Thrift D thrift.server.nonblocking.TNonblockingServer. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-87117 Oct 02, 2026
CVE-2026-87117: Null Pointer Deref in Apache Thrift PHP Bindings before 0.25.0 NULL pointer dereference vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-85087 Oct 02, 2026
Thrift Py Bindings CVE-2026-85087 Improper Cert Val Before 0.25.0 Improper certificate validation, Return of wrong status code vulnerability in Apache Thrift python bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-85086 Oct 02, 2026
Apache Thrift <0.25.0 Improper Cert Validation in Perl Bindings Improper certificate validation, Initialization of a resource with an insecure default vulnerability in Apache Thrift perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-82459 Oct 02, 2026
Apache Thrift Int Underflow/OOB in 32bit THeaderTransport (0.24) Integer underflow (wrap or wraparound), Out-of-bounds write vulnerability in Apache Thrift C++ 32 bit THeaderTransport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-82458 Oct 02, 2026
Memory Allocation DoS in Apache Thrift <0.25.0 (CVE-2026-82458) Memory allocation with excessive size value, Allocation of resources without limits or throttling vulnerability in Apache Thrift Go, netstd, OCaml, Erlang, JavaME, Rust, C++, Java, Kotlin and D language bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-96288 Oct 02, 2026
Apache Thrift Erlang Bindings Uncontrolled Recursion (before 0.25.0) Uncontrolled Recursion, Allocation of resources without limits or throttling vulnerability in Apache Thrift Erlang bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-96292 Oct 02, 2026
Apache Thrift Lua Binding ReDoS before 0.25.0 Inefficient regular expression complexity, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-96294 Oct 02, 2026
Apache Thrift NodeJS Bindings: Improper Exception Handling (pre-0.25.0) Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift NodeJS bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-96990 Oct 02, 2026
Apache Thrift Erlang: Resource Exhaustion before 0.25.0 Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Erlang bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-94644 Oct 02, 2026
Apache Thrift PHP Bindings Resource Exhaustion Pre0.25.0 Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-94645 Oct 02, 2026
Apache Thrift NodeJS Bindings: Unbounded Resource Allocation (0.25.0) Improper validation of specified quantity in input, Allocation of resources without limits or throttling vulnerability in Apache Thrift nodejs bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-94650 Oct 02, 2026
Uncontrolled Recursion in Apache Thrift c_glib Bindings before 0.25.0 Uncontrolled Recursion vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-85483 Oct 02, 2026
Uninitialized resource & wrong status in Apache Thrift c_glib (v<0.25.0) Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-85493 Oct 02, 2026
Apache Thrift Uncontrolled Recursion in Dart/Java ME Bindings (0.24.9) Uncontrolled Recursion vulnerability in Apache Thrift Dart and Java ME bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-85494 Oct 02, 2026
Apache Thrift 0.25.0: Improper Length Handling in Bindings Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python, Ruby, Erlang, Lua, Dart, JavaME, Perl, PHP and D language bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-91137 Oct 02, 2026
Apache Thrift PHP: Improper Qty Validation / Unthrottled Resrc. (0.24.0) Improper validation of specified quantity in input, Allocation of resources without limits or throttling, Excessive Iteration vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-93925 Oct 02, 2026
Apache Thrift: Stack overflow in THeaderProtocol before 0.25.0 Stack-based buffer overflow, Incorrect bitwise shift of integer vulnerability in Apache Thrift C++ THeaderProtocol. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-93926 Oct 02, 2026
Apache Thrift <0.25.0 Memory Leak in THeaderTransport Missing release of memory after effective lifetime, Missing release of resource after effective lifetime vulnerability in Apache Thrift THeaderTransport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-94633 Oct 02, 2026
Memory alloc with excessive size in Apache Thrift Dart bindings before 0.25.0 Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Dart bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-94634 Oct 02, 2026
Apache Thrift Python Bindings Resource Exhaustion Before 0.25.0 Allocation of resources without limits or throttling, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-94635 Oct 02, 2026
Apache Thrift Lua Bindings 0.24 Unbounded Resource Allocation CVE-2026-94635 Allocation of resources without limits or throttling, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-95512 Oct 02, 2026
FreeType CID Font Loader Memory DoS via Repeated Allocations A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate.
Openjdk Els
Enterprise Linux (RHEL)
Hummingbird
And others...
CVE-2026-86345 Oct 01, 2026
389-ds-base LDAP StartTLS buffer injection allows auth bypass A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a client application to treat a failed authentication (bind) attempt as successful.
Directory Server
Enterprise Linux (RHEL)
CVE-2026-86344 Oct 01, 2026
389-ds LDAP Thread Exhaustion DoS via Incomplete LDAPMessage A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to a second worker thread before the first worker's result is flushed. The second worker blocks until nsslapd-ioblocktimeout while holding the connection mutex, preventing delivery of the completed operation's result. Repeating this across a small number of connections proportional to the configured worker-thread pool size exhausts the entire pool under default configuration, denying service to all clients (anonymous and authenticated, plaintext and TLS) for as long as the attacker maintains the connections.
Directory Server
Enterprise Linux (RHEL)
CVE-2026-56098 Oct 01, 2026
Katello RegistryProxiesController Auth Bypass Enables User Enumeration A flaw was found in rubygem-katello. The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registry_authorize filter. While the application identifies unauthorized requests and triggers an error response via the unauthorized method, it fails to halt the execution of the current code path (missing return statement). This failure in the control flow allows the application to proceed into subsequent business logic and database validation filters. Consequently, the application reveals its internal state through differential responses, allowing an unprivileged attacker to enumerate valid Users, Organizations, and Products across the entire instance.
Satellite
Satellite Capsule
Satellite Utils
And others...
CVE-2026-12542 Oct 01, 2026
Foreman Tail Utility OS Command Injection via Unsafe Eval A flaw was found in Foreman. The foreman-tail utility is vulnerable to OS command injection due to the unsafe use of the eval command. The script takes user-supplied arguments and incorporates them directly into a string that is then executed by eval to expand file paths. Because the input is not sanitized or quoted, a local attacker can inject shell metacharacters (e.g., ;, &, |) to execute arbitrary system commands.
Satellite
Satellite Capsule
Satellite Utils
And others...
CVE-2026-12545 Oct 01, 2026
Command Injection in Hammer CLI via $EDITOR Interpolation A flaw was found in rubygem-hammer_cli. A command injection vulnerability exists in Hammer CLI and the Railties (Ruby on Rails) component distributed with Satellite due to the insecure interpolation of the $EDITOR environment variable into the Ruby system() method. By passing a single interpolated string to system(), the application invokes a system shell (/bin/sh) that interprets shell metacharacters (e.g., ;, |, &).
Satellite
Satellite Capsule
Satellite Utils
And others...
CVE-2026-56097 Oct 01, 2026
Red Hat Katello SQLi in RegistryProxiesController A flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries within the RegistryProxiesController. The methods check_blob_push_org_label and get_matching_products_from_org take user-supplied labels directly from the request path and interpolate them into raw SQL fragments. This flaw is accessible to a user with only the create_personal_access_tokens permission, even if the user access is restricted, with no Organization or Location assigned.
Satellite
Satellite Capsule
Satellite Utils
And others...
CVE-2026-96658 Oct 01, 2026
Foreman RCE: SafeMode Templating Bypass A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker can append unauthorized functions to the allowed execution list, enabling them to run arbitrary commands on the hosting server.
Satellite
Satellite Capsule
Satellite Utils
And others...
CVE-2026-96659 Oct 01, 2026
Foreman Viewer Priv Info Disclosure & RCE via Template Preview A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under insecure system configurations where Safemode protections are disabled, the flaw may allow the user to execute arbitrary commands as the Foreman system account.
Satellite
Satellite Capsule
Satellite Utils
And others...
CVE-2026-12544 Oct 01, 2026
Foreman Vulnerable Multi-Stage Execution Enables SSTI & RCE A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a multi-stage execution chain that allows for both Server-Side Template Injection (SSTI) and insecure deserialization. This vulnerability can lead to remote code execution, total infrastructure compromise and supply chain risk.
Satellite
Satellite Capsule
Satellite Utils
And others...
CVE-2026-12541 Oct 01, 2026
Foreman OS Command Injection via foreman-rake db:dump/db:import_dump A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths.
Satellite
Satellite Capsule
Satellite Utils
And others...
CVE-2026-12540 Oct 01, 2026
Foreman Rake Task Command Injection via errors:fetch_log A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo permissions to execute this rake task can inject shell metacharacters (such as ;, ", or |) to break out of the intended command and execute arbitrary code.
Satellite
Satellite Capsule
Satellite Utils
And others...
CVE-2026-12423 Oct 01, 2026
Foreman Auth Bypass via host_verifier.rb in Satellite API A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. Because a host actively undergoing provisioning has an unexpired token in the database, the server's valid_host_token? method evaluates to true, granting access to the kickstart template even if the requester provides no token at all in the URL.
Satellite
Satellite Capsule
Satellite Utils
And others...
CVE-2026-12405 Oct 01, 2026
Red Hat Satellite API Job Injection via rubygem-foreman_remote_execution A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in the Red Hat Satellite API (/api/v2/job_invocations). When a job template has the effective_user property marked as overridable: true, the application fails to properly sanitize the effective_user input provided during the API request. The exploitation does not rely on the content or logic of the Job Template/playbook itself; rather, the injection occurs during the instantiation of the job execution environment by the Satellite server. An attacker with permissions to execute job templates can inject arbitrary shell commands into this parameter, which are executed on the target infrastructure with the privileges of the execution user.
Satellite
Satellite Capsule
Satellite Utils
And others...
CVE-2026-63686 Oct 01, 2026
Apache HTTP Server: NULL pointer deref in mod_xml2enc before 2.4.69 A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
CVE-2026-93546 Oct 01, 2026
Apache HTTP Server 2.4.68 mod_dav_fs Integer Overflow via PROPPATCH Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.
CVE-2026-79768 Oct 01, 2026
Apache HTTP Server 2.4.x Path Equivalence in mod_userdir (UserDir) Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
CVE-2026-73637 Oct 01, 2026
UAF in Apache HTTP Server 2.4 mod_auth_digest before 2.4.69 Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
CVE-2026-73636 Oct 01, 2026
Apache HTTP Server 2.4.x AuthDigestNonceLifetime 0 Bypass via Capture-Replay MITM Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
CVE-2026-63718 Oct 01, 2026
Apache HTTP Server 2.4.30-2.4.68 Response Smuggling via mod_proxy_uwsgi Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68.
CVE-2026-63292 Oct 01, 2026
Apache HTTP 2.4.68 Buffer Overflow via Host Header > 8192 in mod_vhost_alias Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
CVE-2026-63045 Oct 01, 2026
Improper FTP PASV Validation in mod_proxy_ftp (Apache HTTP Server) <2.4.69 Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
CVE-2026-58415 Oct 01, 2026
Apache HTTP Server 2.4.0-2.4.68 mod_dav_fs State File Disclosure Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
CVE-2026-56449 Oct 01, 2026
OOB Write in Apache HTTP Server mod_proxy_html before 2.4.69 Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
CVE-2026-56153 Oct 01, 2026
Out-of-bounds Write in Apache HTTP Server mod_charset_lite (2.4.0-2.4.68) Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
CVE-2026-48005 Oct 01, 2026
Apache HTTP Server 2.4 <2.4.69 mod_auth_digest Digest Auth Bypass DoS Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck . Users are recommended to upgrade to version 2.4.69, which fixes this issue.
CVE-2026-47360 Oct 01, 2026
Apache HTTPD 2.4.0-2.4.68 mod_session_cookie Redirect Cookie Leak Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.   When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.