Skip to content
VulniPulse

Red Hat Linux Web Servers & Proxies Vulnerabilities & Security Advisories

21 advisories tracked · Red Hat Security Data API · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as Web Servers & Proxies, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 9 high, 8 medium, 4 low.

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat Web Servers & Proxies advisories

High7.5Red Hat

High [CVE-2026-63686] Denial of Service via charset conversion failure in mod_xml2enc

Denial of Service via charset conversion failure in mod_xml2enc. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-63686
Web Servers & Proxies
Oct 1, 2026
High8.1Red Hat

High [CVE-2026-73636] Authentication bypass via credential replay in mod_auth_digest

Authentication bypass via credential replay in mod_auth_digest. Red Hat rates this important (CVSS 8.1). Weakness: CWE-294. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-73636
Web Servers & Proxies
Oct 1, 2026
High7.5Red Hat

High [CVE-2026-63718] HTTP response smuggling via crafted Transfer-Encoding response in mod_proxy_uwsgi

HTTP response smuggling via crafted Transfer-Encoding response in mod_proxy_uwsgi. Red Hat rates this important (CVSS 7.5). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-63718
Web Servers & Proxies
Oct 1, 2026
High8.1Red Hat

High [CVE-2026-63292] Arbitrary code execution via oversized Host header in mod_vhost_alias

Arbitrary code execution via oversized Host header in mod_vhost_alias. Red Hat rates this important (CVSS 8.1). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-63292
Web Servers & Proxies
Oct 1, 2026
High7.5Red Hat

High [CVE-2026-56153] Denial of Service via heap-based buffer overflow in mod_charset_lite

Denial of Service via heap-based buffer overflow in mod_charset_lite. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-56153
Web Servers & Proxies
Oct 1, 2026
High7.5Red Hat

High [CVE-2026-46729] Denial of Service via NULL pointer dereference

Denial of Service via NULL pointer dereference. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-46729
Web Servers & Proxies
Oct 1, 2026
Medium5.4Red Hat

Medium [CVE-2026-93546] Denial of Service via integer overflow in mod_dav_fs

Denial of Service via integer overflow in mod_dav_fs. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: httpd.

CVE-2026-93546
Web Servers & Proxies
Oct 1, 2026
Medium5.3Red Hat

Medium [CVE-2026-79768] Information disclosure in mod_userdir via single-dot path equivalence

Information disclosure in mod_userdir via single-dot path equivalence. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-41. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-79768
Web Servers & Proxies
Oct 1, 2026
Medium5.6Red Hat

Medium [CVE-2026-73637] Authentication state corruption via concurrent Digest authentication requests

Authentication state corruption via concurrent Digest authentication requests. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-73637
Web Servers & Proxies
Oct 1, 2026
Medium5.3Red Hat

Medium [CVE-2026-63045] unauthorized connection to arbitrary hosts via crafted FTP PASV response

unauthorized connection to arbitrary hosts via crafted FTP PASV response. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-63045
Web Servers & Proxies
Oct 1, 2026
Medium5.3Red Hat

Medium [CVE-2026-58415] Information disclosure via direct request to the WebDAV state directory

Information disclosure via direct request to the WebDAV state directory. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-552. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-58415
Web Servers & Proxies
Oct 1, 2026
Medium4.3Red Hat

Medium [CVE-2026-42528] Denial of Service via mod_dav shared lock memory calculation error

Denial of Service via mod_dav shared lock memory calculation error. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-131. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-42528
Web Servers & Proxies
Oct 1, 2026
Low3.7Red Hat

Low [CVE-2026-56449] Denial of Service via crafted HTTP response bodies in mod_proxy_html

Denial of Service via crafted HTTP response bodies in mod_proxy_html. Red Hat rates this low (CVSS 3.7). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-56449
Web Servers & Proxies
Oct 1, 2026
Low3.7Red Hat

Low [CVE-2026-48005] Denial of service via forged Authorization headers in mod_auth_digest

Denial of service via forged Authorization headers in mod_auth_digest. Red Hat rates this low (CVSS 3.7). Weakness: CWE-303. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-48005
Web Servers & Proxies
Oct 1, 2026
Low3.7Red Hat

Low [CVE-2026-47360] Information disclosure via session cookie leakage during internal redirects

Information disclosure via session cookie leakage during internal redirects. Red Hat rates this low (CVSS 3.7). Weakness: CWE-212. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-47360
Web Servers & Proxies
Oct 1, 2026
Low3.7Red Hat

Low [CVE-2026-42356] arbitrary code execution via incorrect handler assignment during internal CGI redirects

arbitrary code execution via incorrect handler assignment during internal CGI redirects. Red Hat rates this low (CVSS 3.7). Weakness: CWE-430. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-42356
Web Servers & Proxies
Oct 1, 2026
High8.2Red Hat

High [CVE-2026-60005] Memory disclosure and denial of service in ngx_http_slice_module

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Important: This vulnerability in NGINX's `ngx_http_slice_module` could lead to memory disclosure or denial of service. The impact on Red Hat products is reduced because the `ngx_http_slice_module` is not enabled by default. Exploitation requires explicit configuration of the module with the `slice` directive and unnamed regex captures, or during a background cache update, limiting exposure in typical deployments. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H). Weakness: CWE-824. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Discovery 2; and 4 more.

CVE-2026-60005
Web Servers & Proxies
Jul 15, 2026
High7.0Red Hat

High [CVE-2026-42533] Arbitrary code execution via crafted HTTP requests

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. A flaw was found in NGINX. Additionally, this flaw can cause a denial-of-service (DoS) due to the NGINX worker process restarting. This vulnerability in NGINX allows a remote, unauthenticated attacker to trigger a heap buffer overflow, leading to a denial of service (Dos).

CVE-2026-42533
Web Servers & Proxies
Jul 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-56434] Heap buffer over-read allows memory modification or denial of service

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. A vulnerability in NGINX's ngx_http_ssi_module allows an unauthenticated MITM attacker to trigger a heap buffer over-read by manipulating upstream server responses. This requires SSI, proxy_pass, and proxy_buffering off to be configured, and can result in memory modification or a Denial of Service (DoS). This Moderate severity vulnerability in NGINX affects configurations utilizing the `ngx_http_ssi_module` alongside `proxy_pass` and `proxy_buffering off`. The specific combination of directives and an active MITM position limits the overall impact. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H). Weakness: CWE-125.

CVE-2026-56434
Web Servers & Proxies
Jul 15, 2026
High8.1Red Hat

High [CVE-2026-42055] Arbitrary code execution or Denial of Service via heap-based buffer overflow with crafted HTTP/2 headers

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. A flaw was found in NGINX. When NGINX is configured to proxy HTTP/2 traffic using the ngx_http_proxy_v2_module or ngx_http_grpc_module with specific settings, a remote, unauthenticated attacker can send specially crafted large headers. Under certain conditions, such as when Address Space Layout Randomization (ASLR) is disabled or bypassed, this vulnerability could also allow for arbitrary code execution. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-131.

CVE-2026-42055
Web Servers & Proxies
Jun 17, 2026

← All Red Hat advisories