VDB
GCVE-110-MAGEIA-2026-289
GCVE-110-MAGEIA-2026-289
Advisory Published
The updated packages fix security vulnerabilities:
Apache HTTP Server: mod_ldap per-dir use-after-free. (CVE-2026-29167)
Apache HTTP Server: mod_proxy_ftp XSS. (CVE-2026-29170)
Apache HTTP Server: mod_proxy_html buffer overflow. (CVE-2026-34355)
Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow.
(CVE-2026-34356)
Apache HTTP Server: mod_dav_fs protected directory access.
(CVE-2026-42535)
Apache HTTP Server: mod_xml2enc heap overflow. (CVE-2026-42536)
Apache HTTP Server: OOB Read in `merge_response_headers` can cause
crash. (CVE-2026-43951)
Apache HTTP Server: escalation of privilege through expressions in
.htaccess in multiple modules. (CVE-2026-44119)
Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP
`send_request`. (CVE-2026-44185)
Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp.
(CVE-2026-44186)
Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char
Overflow. (CVE-2026-44631)
Apache HTTP Server: mod_http2 memory corruption when file handles
exhausted. (CVE-2026-48913)
Apache HTTP Server: mod_http2 denial of service. (CVE-2026-49975)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | apache | 0 (affected), 2.4.68-1.mga10 (unaffected) | — |
| Mageia | apache | 0 (affected), 2.4.68-1.mga9 (unaffected) | — |
References
Browse GCVE Records
69,226 records in the GCVE database · Updated August 24, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.