Open Source Security Mailing List

Discussion of security flaws, concepts, and practices in the Open Source community

List Archives

Latest Posts

CVE-2026-103885: Apache Directory LDAP API: Denial of service via crafted telephone number values Emmanuel Lécharny (Oct 02)
Severity: important

Affected versions:

- Apache Directory LDAP API 2.1.0 before 2.1.9

Description:

Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API.

A LDAP server using the LDAP API (like Apache DS) may consume 100% of a CPU core indefinitely when processing some
badly crafted Telephone Numbers.

This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9.

Users are recommended to upgrade to version...

CVE-2026-103880: Apache Directory LDAP API: Denial of service via excessive bcrypt cost factor in stored passwords Emmanuel Lécharny (Oct 02)
Severity: important

Affected versions:

- Apache Directory LDAP API 2.1.0 before 2.1.9

Description:

Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API.

Storing a password using the bcrypt algorithm with a high force like 30 in a LDAP server that supports this algorithm
will cause the server CPU to  run for hours checking the credentials. A bounded cost should be enforced to avoid a
server DOS.

This issue affects...

CVE-2026-103878: Apache Directory LDAP API: Injection of plaintext responses during StartTLS Emmanuel Lécharny (Oct 02)
Severity: important

Affected versions:

- Apache Directory LDAP API 2.1.0 before 2.1.9

Description:

Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API.

A StartTLS extended operation started after a Search request has been sent can lead to receive data in plain text
before the TLS Handshake has been completed.

This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9.

Users are...

CVE-2026-103877: Apache Directory LDAP API: Unsafe loading of Java code from LDAP schema elements Emmanuel Lécharny (Oct 02)
Severity: critical

Affected versions:

- Apache Directory LDAP API 2.1.0 before 2.1.9

Description:

Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API.

A rogue/compromised LDAP server (or pre-TLS MITM) can answer a client's loadSchema() subschema search with a schema
object that contains a serialized Java class, allowing some potential RCE. 

This issue affects Apache Directory LDAP API: from 2.1.0 before...

CVE-2026-103552: Apache Directory LDAP API: A unbound client can send a deeply nested search filter that overflows the stack in the server's decoder Emmanuel Lécharny (Oct 02)
Severity: critical

Affected versions:

- Apache Directory LDAP API 1.2.0 before 1.2.9

Description:

Stack Overflow vulnerability in Apache Directory LDAP API.

Before binding, a client can send a deeply nested search filter that overflows the stack in the server's decoder.

This issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9.

Users are recommended to upgrade to version 1.2.9, which fixes the issue.

Credit:

Claude...

CVE-2026-102731: Apache Directory LDAP API: Denial of service via excessive memory allocation in BER decode Emmanuel Lécharny (Oct 02)
Severity: critical

Affected versions:

- Apache Directory LDAP API 1.2.0 before 1.2.9

Description:

Memory allocation with excessive size value vulnerability in Apache Directory LDAP API.

A malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is
received. This can lead to an OutOfMemoryError and denial of service.

The client JVM OOMs (OutOfMemoryError bypasses the...

CVE-2026-59265: Apache OpenOffice: Opening a malicious document can lead to system takeover Dave Fisher (Oct 02)
Severity: critical

Affected versions:

- Apache OpenOffice through 4.1.16
- Apache OpenOffice before 95923fd437e06edd38a4f0e139a27c755a6f3ba6
- Apache OpenOffice before 181421139242694b309751fb666406eddc203c50

Description:

A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted
document to trigger executing arbitrary (even remote) code when opened by the user.

This issue is expected...

CVE-2026-102795: Apache Traffic Server: SNI to Host header matching policy is not properly enforced (supersedes CVE-2026-41920) Masakazu Kitajo (Oct 02)
Severity: moderate

Affected versions:

- Apache Traffic Server 9.0.0 through 9.2.14
- Apache Traffic Server 10.0.0 through 10.1.3

Description:

Improper Access Control vulnerability in Apache Traffic Server.

This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from
10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes
the issue.

This CVE supersedes CVE-2026-41920, whose record listed...

CVE-2026-93546: Apache HTTP Server: mod_dav_fs namespace overflow Eric Covener (Oct 01)
Severity: moderate

Affected versions:

- Apache HTTP Server through 2.4.68

Description:

Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write
access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests
declaring many XML namespaces.

Credit:

Zhen Kong (finder)
Calif.io in collaboration with Anthropic (finder)
AISLE in...

CVE-2026-79768: Apache HTTP Server: mod_userdir information disclosure Eric Covener (Oct 01)
Severity: low

Affected versions:

- Apache HTTP Server 2.4.0 through 2.4.68

Description:

Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured
with absolute non-wildcard UserDir directive (the 2nd form in 
https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir)

This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Credit:

Vlatko...

CVE-2026-73637: Apache HTTP Server: mod_auth_digest DoS attack Eric Covener (Oct 01)
Severity: low

Affected versions:

- Apache HTTP Server 2.4.0 through 2.4.68

Description:

Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms
allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication
requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.

Users are recommended to upgrade to...

CVE-2026-73636: Apache HTTP Server: mod_auth_digest one-time-nonce replay attack Eric Covener (Oct 01)
Severity: low

Affected versions:

- Apache HTTP Server 2.4.0 through 2.4.68

Description:

Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on
all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via
crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is...

CVE-2026-63718: Apache HTTP Server: mod_proxy_uwsgi Transfer-Encoding response smuggling Eric Covener (Oct 01)
Severity: low

Affected versions:

- Apache HTTP Server 2.4.30 through 2.4.68

Description:

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in
Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding.

This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68.

Credit:

Qing Xu (finder)

References:...

CVE-2026-63686: Apache HTTP Server: mod_xml2enc crash on charset conversion failure Eric Covener (Oct 01)
Severity: low

Affected versions:

- Apache HTTP Server 2.4.0 through 2.4.68

Description:

A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all
platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose
conversion partially succeeds then fails.

Users are recommended to upgrade to version 2.4.69, which fixes this issue....

CVE-2026-63292: Apache HTTP Server: mod_vhost_alias stack overflow Eric Covener (Oct 01)
Severity: moderate

Affected versions:

- Apache HTTP Server 2.4.0 through 2.4.68

Description:

Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all
platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request
with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and...

More Lists

Dozens of other network security lists are archived at SecLists.Org.