Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
CLSA-2026-1778254552
See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/rhel7els/CLSA-2026-1778254552.json
JSON Data
https://api.osv.dev/v1/vulns/CLSA-2026-1778254552
Upstream
CVE-2026-24072
CVE-2026-29169
CVE-2026-33006
CVE-2026-33007
CVE-2026-33523
CVE-2026-33857
CVE-2026-34032
CVE-2026-34059
Published
2026-05-08T15:36:12Z
Modified
2026-06-01T00:33:28Z
Summary
httpd: Fix of 8 CVEs
Details
CVE-2026-24072: mod_rewrite/mod_setenvif: use AP_EXPR_FLAG_RESTRICTED in htaccess to prevent reading server-side files via ap_expr from .htaccess
CVE-2026-29169: mod_dav_lock: NULL pointer dereference in dav_generic_refresh_locks (use dp_scan instead of dp)
CVE-2026-33006: mod_auth_digest: timing attack — use constant-time compare for nonce/digest verification
CVE-2026-33007: mod_authn_socache: NULL pointer dereference when r->uri has no '/' in directory context
CVE-2026-33523: scan outgoing status line for newlines and control characters to prevent HTTP response splitting
CVE-2026-33857: mod_proxy_ajp: off-by-one OOB reads in ajp_msg_get/peek length checks
CVE-2026-34032: mod_proxy_ajp: improper null termination and OOB read in ajp_msg_get_string
CVE-2026-34059: mod_proxy_ajp: heap over-read in ajp_parse_data when message is too small
References
https://errata.tuxcare.com/els_os/rhel7els/CLSA-2026-1778254552.html
Affected packages
TuxCare:RHEL:7
httpd
Package
Name
httpd
Purl
pkg:rpm/tuxcare/httpd?distro=rhel-7
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.4.6-99.0.5.el7_9.1.tuxcare.els10
Database specific
source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/rhel7els/CLSA-2026-1778254552.json"
httpd-devel
Package
Name
httpd-devel
Purl
pkg:rpm/tuxcare/httpd-devel?distro=rhel-7
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.4.6-99.0.5.el7_9.1.tuxcare.els10
Database specific
source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/rhel7els/CLSA-2026-1778254552.json"
httpd-manual
Package
Name
httpd-manual
Purl
pkg:rpm/tuxcare/httpd-manual?distro=rhel-7
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.4.6-99.0.5.el7_9.1.tuxcare.els10
Database specific
source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/rhel7els/CLSA-2026-1778254552.json"
httpd-tools
Package
Name
httpd-tools
Purl
pkg:rpm/tuxcare/httpd-tools?distro=rhel-7
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.4.6-99.0.5.el7_9.1.tuxcare.els10
Database specific
source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/rhel7els/CLSA-2026-1778254552.json"
mod_ldap
Package
Name
mod_ldap
Purl
pkg:rpm/tuxcare/mod_ldap?distro=rhel-7
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.4.6-99.0.5.el7_9.1.tuxcare.els10
Database specific
source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/rhel7els/CLSA-2026-1778254552.json"
mod_proxy_html
Package
Name
mod_proxy_html
Purl
pkg:rpm/tuxcare/mod_proxy_html?distro=rhel-7
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:2.4.6-99.0.5.el7_9.1.tuxcare.els10
Database specific
source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/rhel7els/CLSA-2026-1778254552.json"
mod_session
Package
Name
mod_session
Purl
pkg:rpm/tuxcare/mod_session?distro=rhel-7
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.4.6-99.0.5.el7_9.1.tuxcare.els10
Database specific
source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/rhel7els/CLSA-2026-1778254552.json"
mod_ssl
Package
Name
mod_ssl
Purl
pkg:rpm/tuxcare/mod_ssl?distro=rhel-7
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:2.4.6-99.0.5.el7_9.1.tuxcare.els10
Database specific
source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/rhel7els/CLSA-2026-1778254552.json"
CLSA-2026-1778254552 - OSV