Overview
- Apache Software Foundation
- Apache HTTP Server
01 Oct 2026
Published
01 Oct 2026
Updated
CVSS
Pending
EPSS
Pending
KEV
Description
Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default.
Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Statistics
- 1 Post
Last activity: 6 hours ago
Overview
- Apache Software Foundation
- Apache HTTP Server
01 Oct 2026
Published
01 Oct 2026
Updated
CVSS
Pending
EPSS
Pending
KEV
Description
Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Statistics
- 1 Post
Last activity: 6 hours ago
Overview
- Apache Software Foundation
- Apache HTTP Server
01 Oct 2026
Published
01 Oct 2026
Updated
CVSS
Pending
EPSS
Pending
KEV
Description
Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.
Statistics
- 1 Post
Last activity: 6 hours ago
Overview
- open-telemetry
- opentelemetry-go
16 Sep 2026
Published
17 Sep 2026
Updated
CVSS v4.0
LOW (2.0)
EPSS
0.20%
KEV
Description
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively include span processor, exporter, and client configuration. Applications that call otel.SetLogger to enable OpenTelemetry internal Info logging can therefore record OTLP gRPC and HTTP collector endpoints, the OTLP HTTP Insecure flag, and complete Zipkin collector URLs. A person or system with access to those logs can learn internal collector topology and can recover credentials or tokens embedded in Zipkin URL user information or query strings. The default OpenTelemetry logger does not emit the event, and this path does not log OTLP authentication headers, TLS key material, or span payloads. This issue is fixed in version 1.45.0.
Statistics
- 2 Posts
Last activity: 4 hours ago
Overview
- FasterXML
- jackson-databind
23 Jun 2026
Published
25 Jun 2026
Updated
CVSS v3.1
MEDIUM (5.3)
EPSS
0.37%
KEV
Description
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
Statistics
- 1 Post
Last activity: 4 hours ago
Overview
- Go toolchain
- cmd/go
- cmd/go
13 Aug 2026
Published
14 Aug 2026
Updated
CVSS
Pending
EPSS
0.14%
KEV
Description
A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. This attack allows for a malicious GOPROXY to serve malicious module content that cannot be detected by evaluating the transparency log. All tiles are now correctly verified against their parents. In order to determine if you have been affected: rm -r go.sum go.work.sum vendor/ && go mod tidy
Statistics
- 1 Post
Last activity: 4 hours ago
Overview
- Go standard library
- net
- net
21 Jul 2026
Published
14 Aug 2026
Updated
CVSS
Pending
EPSS
0.63%
KEV
Description
Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
Statistics
- 1 Post
Last activity: 4 hours ago
Overview
- Go standard library
- net/url
- net/url
13 Aug 2026
Published
14 Aug 2026
Updated
CVSS
Pending
EPSS
0.55%
KEV
Description
Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.
Statistics
- 2 Posts
Last activity: 4 hours ago
Bluesky
following vulnerability: CVE-2026-84445 N/A Security fixes for apigee-prom-prometheus. This addresses the following vulnerabilities: CVE-2026-33818 CVE-2026-39821 CVE-2026-46600 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 CVE-2026-56864
Overview
- Go standard library
- net/http
- net/http
13 Aug 2026
Published
14 Aug 2026
Updated
CVSS
Pending
EPSS
0.57%
KEV
Description
When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.
Statistics
- 2 Posts
Last activity: 4 hours ago
Bluesky
following vulnerability: CVE-2026-84445 N/A Security fixes for apigee-prom-prometheus. This addresses the following vulnerabilities: CVE-2026-33818 CVE-2026-39821 CVE-2026-46600 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 CVE-2026-56864
Overview
- Go toolchain
- cmd/go
- cmd/go
13 Aug 2026
Published
14 Aug 2026
Updated
CVSS
Pending
EPSS
0.32%
KEV
Description
A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you have been affected: rm -r go.sum go.work.sum vendor/ && go mod tidy
Statistics
- 2 Posts
Last activity: 4 hours ago
Bluesky
following vulnerability: CVE-2026-84445 N/A Security fixes for apigee-prom-prometheus. This addresses the following vulnerabilities: CVE-2026-33818 CVE-2026-39821 CVE-2026-46600 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 CVE-2026-56864