MGASA-2026-0289

Source
https://advisories.mageia.org/MGASA-2026-0289.html
Import Source
https://advisories.mageia.org/MGASA-2026-0289.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2026-0289
Upstream
  • CVE-2026-29167
  • CVE-2026-29170
  • CVE-2026-34355
  • CVE-2026-34356
  • CVE-2026-42535
  • CVE-2026-42536
  • CVE-2026-43951
  • CVE-2026-44119
  • CVE-2026-44185
  • CVE-2026-44186
  • CVE-2026-44631
  • CVE-2026-48913
Published
2026-07-23T17:45:56Z
Modified
2026-07-23T18:00:06.877487383Z
Summary
Updated apache packages fix security vulnerabilities
Details

The updated packages fix security vulnerabilities: Apache HTTP Server: modldap per-dir use-after-free. (CVE-2026-29167) Apache HTTP Server: modproxyftp XSS. (CVE-2026-29170) Apache HTTP Server: modproxyhtml buffer overflow. (CVE-2026-34355) Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow. (CVE-2026-34356) Apache HTTP Server: moddavfs protected directory access. (CVE-2026-42535) Apache HTTP Server: modxml2enc heap overflow. (CVE-2026-42536) Apache HTTP Server: OOB Read in merge_response_headers can cause crash. (CVE-2026-43951) Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules. (CVE-2026-44119) Apache HTTP Server: Stack Buffer Over-Read in modssl OCSP send_request. (CVE-2026-44185) Apache HTTP Server: Loop in proxy_ftp_handler in modproxyftp. (CVE-2026-44186) Apache HTTP Server: Heap Underflow in ap_regname via Signed Char Overflow. (CVE-2026-44631) Apache HTTP Server: modhttp2 memory corruption when file handles exhausted. (CVE-2026-48913) Apache HTTP Server: mod_http2 denial of service. (CVE-2026-49975)

References
Credits

Affected packages

Mageia:10 / apache

Package

Name
apache
Purl
pkg:rpm/mageia/apache?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.68-1.mga10

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0289.json"

Mageia:9 / apache

Package

Name
apache
Purl
pkg:rpm/mageia/apache?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.68-1.mga9

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0289.json"