Skip to content
VulniPulse

Red Hat Linux Web Servers & Proxies Vulnerabilities & Security Advisories

21 advisories tracked · Red Hat Security Data API · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as Web Servers & Proxies, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 9 high, 8 medium, 4 low.

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat Web Servers & Proxies advisories

Medium5.4Red Hat

Medium [CVE-2026-93546] Denial of Service via integer overflow in mod_dav_fs

Denial of Service via integer overflow in mod_dav_fs. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: httpd.

CVE-2026-93546
Web Servers & Proxies
Oct 1, 2026
Medium5.3Red Hat

Medium [CVE-2026-79768] Information disclosure in mod_userdir via single-dot path equivalence

Information disclosure in mod_userdir via single-dot path equivalence. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-41. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-79768
Web Servers & Proxies
Oct 1, 2026
Medium5.6Red Hat

Medium [CVE-2026-73637] Authentication state corruption via concurrent Digest authentication requests

Authentication state corruption via concurrent Digest authentication requests. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-73637
Web Servers & Proxies
Oct 1, 2026
Medium5.3Red Hat

Medium [CVE-2026-63045] unauthorized connection to arbitrary hosts via crafted FTP PASV response

unauthorized connection to arbitrary hosts via crafted FTP PASV response. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-63045
Web Servers & Proxies
Oct 1, 2026
Medium5.3Red Hat

Medium [CVE-2026-58415] Information disclosure via direct request to the WebDAV state directory

Information disclosure via direct request to the WebDAV state directory. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-552. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-58415
Web Servers & Proxies
Oct 1, 2026
Medium4.3Red Hat

Medium [CVE-2026-42528] Denial of Service via mod_dav shared lock memory calculation error

Denial of Service via mod_dav shared lock memory calculation error. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-131. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-42528
Web Servers & Proxies
Oct 1, 2026
Medium6.5Red Hat

Medium [CVE-2026-56434] Heap buffer over-read allows memory modification or denial of service

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. A vulnerability in NGINX's ngx_http_ssi_module allows an unauthenticated MITM attacker to trigger a heap buffer over-read by manipulating upstream server responses. This requires SSI, proxy_pass, and proxy_buffering off to be configured, and can result in memory modification or a Denial of Service (DoS). This Moderate severity vulnerability in NGINX affects configurations utilizing the `ngx_http_ssi_module` alongside `proxy_pass` and `proxy_buffering off`. The specific combination of directives and an active MITM position limits the overall impact. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H). Weakness: CWE-125.

CVE-2026-56434
Web Servers & Proxies
Jul 15, 2026
Medium4.8Red Hat

Medium [CVE-2026-48142] Memory disclosure or denial of service via ngx_http_charset_module heap buffer over-read

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. A flaw was found in NGINX. Remote, unauthenticated attackers can exploit a vulnerability in the `ngx_http_charset_module` when specific charset configurations are present. Red Hat severity: Moderate — CVSS 4.8 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:27197. Affected products named by the advisory: Red Hat package: nginx.

CVE-2026-48142
Web Servers & Proxies
Jun 17, 2026

← All Red Hat advisories