Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
CLSA-2026-1778254552
See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/rhel7els/CLSA-2026-1778254552.json
JSON Data
https://api.osv.dev/v1/vulns/CLSA-2026-1778254552
Upstream
CVE-2026-24072
CVE-2026-29169
CVE-2026-33006
CVE-2026-33007
CVE-2026-33523
CVE-2026-33857
CVE-2026-34032
CVE-2026-34059
Published
2026-05-08T15:36:12Z
Modified
2026-06-01T00:33:28.276431402Z
Summary
httpd: Fix of 8 CVEs
Details
CVE-2026-24072: mod
rewrite/mod
setenvif: use AP
EXPR
FLAG
RESTRICTED in htaccess to prevent reading server-side files via ap
expr from .htaccess
CVE-2026-29169: mod
dav
lock: NULL pointer dereference in dav
generic
refresh
locks (use dp
scan instead of dp)
CVE-2026-33006: mod
auth
digest: timing attack — use constant-time compare for nonce/digest verification
CVE-2026-33007: mod
authn
socache: NULL pointer dereference when r->uri has no '/' in directory context
CVE-2026-33523: scan outgoing status line for newlines and control characters to prevent HTTP response splitting
CVE-2026-33857: mod
proxy
ajp: off-by-one OOB reads in ajp
msg
get/peek length checks
CVE-2026-34032: mod
proxy
ajp: improper null termination and OOB read in ajp
msg
get_string
CVE-2026-34059: mod
proxy
ajp: heap over-read in ajp
parse
data when message is too small
References
https://errata.tuxcare.com/els_os/rhel7els/CLSA-2026-1778254552.html
Affected packages
TuxCare:RHEL:7
httpd
Package
Name
httpd
Purl
pkg:rpm/tuxcare/httpd?distro=rhel-7
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.4.6-99.0.5.el7_9.1.tuxcare.els10
Database specific
source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/rhel7els/CLSA-2026-1778254552.json"
httpd-devel
Package
Name
httpd-devel
Purl
pkg:rpm/tuxcare/httpd-devel?distro=rhel-7
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.4.6-99.0.5.el7_9.1.tuxcare.els10
Database specific
source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/rhel7els/CLSA-2026-1778254552.json"
httpd-manual
Package
Name
httpd-manual
Purl
pkg:rpm/tuxcare/httpd-manual?distro=rhel-7
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.4.6-99.0.5.el7_9.1.tuxcare.els10
Database specific
source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/rhel7els/CLSA-2026-1778254552.json"
httpd-tools
Package
Name
httpd-tools
Purl
pkg:rpm/tuxcare/httpd-tools?distro=rhel-7
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.4.6-99.0.5.el7_9.1.tuxcare.els10
Database specific
source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/rhel7els/CLSA-2026-1778254552.json"
mod_ldap
Package
Name
mod_ldap
Purl
pkg:rpm/tuxcare/mod_ldap?distro=rhel-7
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.4.6-99.0.5.el7_9.1.tuxcare.els10
Database specific
source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/rhel7els/CLSA-2026-1778254552.json"
mod_proxy_html
Package
Name
mod_proxy_html
Purl
pkg:rpm/tuxcare/mod_proxy_html?distro=rhel-7
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:2.4.6-99.0.5.el7_9.1.tuxcare.els10
Database specific
source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/rhel7els/CLSA-2026-1778254552.json"
mod_session
Package
Name
mod_session
Purl
pkg:rpm/tuxcare/mod_session?distro=rhel-7
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.4.6-99.0.5.el7_9.1.tuxcare.els10
Database specific
source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/rhel7els/CLSA-2026-1778254552.json"
mod_ssl
Package
Name
mod_ssl
Purl
pkg:rpm/tuxcare/mod_ssl?distro=rhel-7
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:2.4.6-99.0.5.el7_9.1.tuxcare.els10
Database specific
source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/rhel7els/CLSA-2026-1778254552.json"
CLSA-2026-1778254552 - OSV