CVE tracker
394 subscribers
5.75K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-21833 - HCL AION is susceptible to a Missing "Content-Security-Policy" header Vulnerability (CVE-2026-21833)

CVE ID :CVE-2026-21833
Published : Oct. 1, 2026, 5:17 p.m. | 22 minutes ago
Description :HCL AION is affected by a vulnerability in which the Content-Security-Policy (CSP) HTTP response header is not configured. CSP helps prevent attacks such as Cross-Site Scripting (XSS) by restricting the sources from which scripts, styles, and other resources can be loaded. The absence of this header may reduce the effectiveness of browser-based security controls, potentially resulting in unintended behavior or negative security impacts under certain conditions.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48005 - Apache HTTP Server: mod_auth_digest reauthentication attack

CVE ID :CVE-2026-48005
Published : Oct. 1, 2026, 5:17 p.m. | 22 minutes ago
Description :Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck . Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-56153 - Apache HTTP Server: mod_charset_lite: Heap overflow in finish_partial_char

CVE ID :CVE-2026-56153
Published : Oct. 1, 2026, 5:17 p.m. | 22 minutes ago
Description :Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-56154 - Apache HTTP Server: mod_rewrite use-after-free via %{LA-U:HTTP:...}

CVE ID :CVE-2026-56154
Published : Oct. 1, 2026, 5:17 p.m. | 22 minutes ago
Description :Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-56449 - Apache HTTP Server: mod_proxy_html: crash in dump_content

CVE ID :CVE-2026-56449
Published : Oct. 1, 2026, 5:17 p.m. | 22 minutes ago
Description :Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-57941 - Apache HTTP Server: mod_http2 use-after-free / wild write via shared session->bbtmp re-entrancy

CVE ID :CVE-2026-57941
Published : Oct. 1, 2026, 5:17 p.m. | 22 minutes ago
Description :Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58415 - Apache HTTP Server: mod_dav_fs property database read access

CVE ID :CVE-2026-58415
Published : Oct. 1, 2026, 5:17 p.m. | 22 minutes ago
Description :Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59685 - Apache HTTP Server: Out-of-Bounds Write in ap_directory_walk() Canonical-Name Rewrite on CASE_BLIND_FILESYSTEM

CVE ID :CVE-2026-59685
Published : Oct. 1, 2026, 5:17 p.m. | 22 minutes ago
Description :Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59797 - Apache HTTP Server: mod_ssl SSLRequire allows .htaccess ap_expr file-function

CVE ID :CVE-2026-59797
Published : Oct. 1, 2026, 5:17 p.m. | 22 minutes ago
Description :Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-63045 - Apache HTTP Server: mod_proxy_ftp PASV address handling

CVE ID :CVE-2026-63045
Published : Oct. 1, 2026, 5:17 p.m. | 22 minutes ago
Description :Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-63292 - Apache HTTP Server: mod_vhost_alias stack overflow

CVE ID :CVE-2026-63292
Published : Oct. 1, 2026, 5:17 p.m. | 22 minutes ago
Description :Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-63686 - Apache HTTP Server: mod_xml2enc crash on charset conversion failure

CVE ID :CVE-2026-63686
Published : Oct. 1, 2026, 5:17 p.m. | 22 minutes ago
Description :A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-63718 - Apache HTTP Server: mod_proxy_uwsgi Transfer-Encoding response smuggling

CVE ID :CVE-2026-63718
Published : Oct. 1, 2026, 5:17 p.m. | 22 minutes ago
Description :Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67171 - HCL BigFix Service Management is affected by multiple security vulnerabilities.

CVE ID :CVE-2026-67171
Published : Oct. 1, 2026, 5:17 p.m. | 22 minutes ago
Description :HCL BigFix Service Management is affected by an Information Disclosure vulnerability because an exposed API endpoint exposes sensitive internal database information. This information could enable an attacker to facilitate targeted database attacks.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67172 - HCL BigFix Service Management is affected by multiple security vulnerabilities.

CVE ID :CVE-2026-67172
Published : Oct. 1, 2026, 5:17 p.m. | 22 minutes ago
Description :HCL BigFix Service Management is affected by an Information Disclosure vulnerability the application returns sensitive information in error messages when invalid inputs are sent to certain API endpoints . This information could enable an attacker to facilitate further attacks.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73636 - Apache HTTP Server: mod_auth_digest one-time-nonce replay attack

CVE ID :CVE-2026-73636
Published : Oct. 1, 2026, 5:17 p.m. | 22 minutes ago
Description :Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73637 - Apache HTTP Server: mod_auth_digest DoS attack

CVE ID :CVE-2026-73637
Published : Oct. 1, 2026, 5:17 p.m. | 22 minutes ago
Description :Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73975 - djehuty: Authenticated SPARQL injection in session editing allows writing arbitrary RDF triples

CVE ID :CVE-2026-73975
Published : Oct. 1, 2026, 5:17 p.m. | 22 minutes ago
Description :djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, an authenticated depositor can inject arbitrary SPARQL into a state-modifying (DELETE/INSERT) query by supplying a crafted session name, letting them write (and delete) arbitrary triples anywhere in the RDF store. Because the RDF store is shared across all accounts and datasets, this is an integrity compromise of the whole repository's metadata, not just the attacker's own records. Having a logged-in account is a precondition. djehuty allows self-registration via ORCID/SAML, so this is a low barrier in typical deployments. This issue has been patched in version 26.3.2.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77387 - geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point

CVE ID :CVE-2026-77387
Published : Oct. 1, 2026, 5:17 p.m. | 22 minutes ago
Description :geopy is a geocoding library for Python. Prior to 2.5.0, geopy.Point and Point.from_string() can spend excessive CPU time due to inefficient regular-expression behavior when an application passes a long malformed coordinate string without the 256-character input limit used by the fix. Geocoder reverse methods also reach the vulnerable parsing path when called with string inputs. Repeated attacker-controlled requests can cause a denial of service, while the numeric Point constructor is unaffected. This issue is fixed in version 2.5.0.
Severity: 4.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-79768 - Apache HTTP Server: mod_userdir information disclosure

CVE ID :CVE-2026-79768
Published : Oct. 1, 2026, 5:17 p.m. | 22 minutes ago
Description :Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93546 - Apache HTTP Server: mod_dav_fs namespace overflow

CVE ID :CVE-2026-93546
Published : Oct. 1, 2026, 5:17 p.m. | 22 minutes ago
Description :Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...