<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<!-- MHonArc v2.6.19+ -->
  <channel>
    <title>announce</title>
    <link>http://www.mail-archive.com/announce@httpd.apache.org</link>
    <description>announce @ httpd.apache</description>
    <pubDate>Fri, 05 Dec 2025 07:16:22 GMT</pubDate>
    <lastBuildDate>Fri, 05 Dec 2025 07:16:22 GMT</lastBuildDate>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <generator>MHonArc RSS 2.0 RCFile</generator>
    <webMaster>themailarchive@gmail.com (The Mail Archive)</webMaster>
    <image>
       <title>The Mail Archive</title>
       <url>http://www.mail-archive.com/nanologo.png</url>
       <link>http://www.mail-archive.com/announce@httpd.apache.org</link>
    </image>
 
    <item>
      <title>CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00191.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/12/05&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Eric Covener%22&quot;&gt;Eric Covener&lt;/a&gt;</description>
      <pubDate>Fri, 05 Dec 2025 07:16:21 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00191.html</guid>
   </item>
    <item>
      <title>CVE-2025-58098: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00190.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/12/05&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Eric Covener%22&quot;&gt;Eric Covener&lt;/a&gt;</description>
      <pubDate>Fri, 05 Dec 2025 07:10:58 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00190.html</guid>
   </item>
    <item>
      <title>CVE-2025-55753: Apache HTTP Server: mod_md (ACME), unintended retry intervals</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00189.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/12/05&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Eric Covener%22&quot;&gt;Eric Covener&lt;/a&gt;</description>
      <pubDate>Fri, 05 Dec 2025 07:05:00 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00189.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.66 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00188.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/12/04&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22covener%22&quot;&gt;covener&lt;/a&gt;</description>
      <pubDate>Thu, 04 Dec 2025 14:09:20 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00188.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.65 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00187.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/07/23&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22covener%22&quot;&gt;covener&lt;/a&gt;</description>
      <pubDate>Wed, 23 Jul 2025 12:23:16 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00187.html</guid>
   </item>
    <item>
      <title>CVE-2025-54090: Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00186.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/07/23&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Eric Covener%22&quot;&gt;Eric Covener&lt;/a&gt;</description>
      <pubDate>Wed, 23 Jul 2025 12:18:27 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00186.html</guid>
   </item>
    <item>
      <title>CVE-2024-47252: Apache HTTP Server: mod_ssl error log variable escaping</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00185.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/07/11&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Eric Covener%22&quot;&gt;Eric Covener&lt;/a&gt;</description>
      <pubDate>Fri, 11 Jul 2025 09:50:35 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00185.html</guid>
   </item>
    <item>
      <title>CVE-2024-43204: Apache HTTP Server: SSRF with mod_headers setting Content-Type header</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00184.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/07/11&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Eric Covener%22&quot;&gt;Eric Covener&lt;/a&gt;</description>
      <pubDate>Fri, 11 Jul 2025 09:47:48 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00184.html</guid>
   </item>
    <item>
      <title>CVE-2024-43394: Apache HTTP Server: SSRF on Windows due to UNC paths</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00183.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/07/11&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Eric Covener%22&quot;&gt;Eric Covener&lt;/a&gt;</description>
      <pubDate>Fri, 11 Jul 2025 09:43:28 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00183.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.64 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00182.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/07/10&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22covener%22&quot;&gt;covener&lt;/a&gt;</description>
      <pubDate>Thu, 10 Jul 2025 15:59:46 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00182.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.63 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00181.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/01/23&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22jim%22&quot;&gt;jim&lt;/a&gt;</description>
      <pubDate>Thu, 23 Jan 2025 21:01:27 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00181.html</guid>
   </item>
    <item>
      <title>CVE-2024-40725: Apache HTTP Server: source code disclosure with handlers configured via AddType</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00180.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/07/17&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Eric Covener%22&quot;&gt;Eric Covener&lt;/a&gt;</description>
      <pubDate>Wed, 17 Jul 2024 18:32:28 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00180.html</guid>
   </item>
    <item>
      <title>CVE-2024-40898: Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00179.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/07/17&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Eric Covener%22&quot;&gt;Eric Covener&lt;/a&gt;</description>
      <pubDate>Wed, 17 Jul 2024 18:29:01 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00179.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.61 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00178.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/07/03&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22covener%22&quot;&gt;covener&lt;/a&gt;</description>
      <pubDate>Wed, 03 Jul 2024 15:10:15 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00178.html</guid>
   </item>
    <item>
      <title>CVE-2024-36387: Apache HTTP Server: DoS by Null pointer in websocket over HTTP/2</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00177.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/07/01&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Eric Covener%22&quot;&gt;Eric Covener&lt;/a&gt;</description>
      <pubDate>Mon, 01 Jul 2024 13:24:45 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00177.html</guid>
   </item>
    <item>
      <title>CVE-2024-38473: Apache HTTP Server proxy encoding problem</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00176.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/07/01&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Eric Covener%22&quot;&gt;Eric Covener&lt;/a&gt;</description>
      <pubDate>Mon, 01 Jul 2024 13:14:50 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00176.html</guid>
   </item>
    <item>
      <title>CVE-2024-38472: Apache HTTP Server on WIndows UNC SSRF</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00175.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/07/01&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Eric Covener%22&quot;&gt;Eric Covener&lt;/a&gt;</description>
      <pubDate>Mon, 01 Jul 2024 13:14:20 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00175.html</guid>
   </item>
    <item>
      <title>CVE-2024-38475: Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00174.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/07/01&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Eric Covener%22&quot;&gt;Eric Covener&lt;/a&gt;</description>
      <pubDate>Mon, 01 Jul 2024 13:08:06 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00174.html</guid>
   </item>
    <item>
      <title>CVE-2024-38474: Apache HTTP Server weakness with encoded question marks in backreferences</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00173.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/07/01&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Eric Covener%22&quot;&gt;Eric Covener&lt;/a&gt;</description>
      <pubDate>Mon, 01 Jul 2024 13:04:58 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00173.html</guid>
   </item>
    <item>
      <title>CVE-2024-38476: Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00172.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/07/01&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Eric Covener%22&quot;&gt;Eric Covener&lt;/a&gt;</description>
      <pubDate>Mon, 01 Jul 2024 13:00:32 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00172.html</guid>
   </item>
    <item>
      <title>CVE-2024-38477: Apache HTTP Server: Crash resulting in Denial of Service in mod_proxy via a malicious request</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00171.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/07/01&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Eric Covener%22&quot;&gt;Eric Covener&lt;/a&gt;</description>
      <pubDate>Mon, 01 Jul 2024 12:57:37 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00171.html</guid>
   </item>
    <item>
      <title>CVE-2024-39573: Apache HTTP Server: mod_rewrite proxy handler substitution</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00170.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/07/01&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Eric Covener%22&quot;&gt;Eric Covener&lt;/a&gt;</description>
      <pubDate>Mon, 01 Jul 2024 12:53:17 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00170.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.60 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00169.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/07/01&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22covener%22&quot;&gt;covener&lt;/a&gt;</description>
      <pubDate>Mon, 01 Jul 2024 12:50:49 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00169.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.59 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00168.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/04/04&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22covener%22&quot;&gt;covener&lt;/a&gt;</description>
      <pubDate>Thu, 04 Apr 2024 14:02:33 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00168.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.58 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00167.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2023/10/19&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22icing%22&quot;&gt;icing&lt;/a&gt;</description>
      <pubDate>Thu, 19 Oct 2023 09:37:01 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00167.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.57 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00166.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2023/04/06&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22covener%22&quot;&gt;covener&lt;/a&gt;</description>
      <pubDate>Thu, 06 Apr 2023 17:42:46 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00166.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.56 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00165.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2023/03/09&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22covener%22&quot;&gt;covener&lt;/a&gt;</description>
      <pubDate>Thu, 09 Mar 2023 12:32:56 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00165.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.55 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00164.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2023/01/17&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22covener%22&quot;&gt;covener&lt;/a&gt;</description>
      <pubDate>Tue, 17 Jan 2023 17:18:11 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00164.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.53 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00163.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2022/03/14&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22icing%22&quot;&gt;icing&lt;/a&gt;</description>
      <pubDate>Mon, 14 Mar 2022 10:01:13 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00163.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.50 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00162.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2021/10/05&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22icing%22&quot;&gt;icing&lt;/a&gt;</description>
      <pubDate>Tue, 05 Oct 2021 08:46:06 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00162.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.49 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00161.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2021/09/16&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22icing%22&quot;&gt;icing&lt;/a&gt;</description>
      <pubDate>Thu, 16 Sep 2021 10:18:07 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00161.html</guid>
   </item>
    <item>
      <title>CVE-2021-31618: NULL pointer dereference on specially crafted HTTP/2 request</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00160.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2021/06/10&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Christophe JAILLET%22&quot;&gt;Christophe JAILLET&lt;/a&gt;</description>
      <pubDate>Thu, 10 Jun 2021 09:29:44 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00160.html</guid>
   </item>
    <item>
      <title>CVE-2021-26691: mod_session response handling heap overflow</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00159.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2021/06/10&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Christophe JAILLET%22&quot;&gt;Christophe JAILLET&lt;/a&gt;</description>
      <pubDate>Thu, 10 Jun 2021 09:22:11 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00159.html</guid>
   </item>
    <item>
      <title>CVE-2021-30641: Unexpected URL matching with 'MergeSlashes OFF'</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00158.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2021/06/10&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Christophe JAILLET%22&quot;&gt;Christophe JAILLET&lt;/a&gt;</description>
      <pubDate>Thu, 10 Jun 2021 09:19:29 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00158.html</guid>
   </item>
    <item>
      <title>CVE-2021-26690: mod_session NULL pointer dereference</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00157.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2021/06/10&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Christophe JAILLET%22&quot;&gt;Christophe JAILLET&lt;/a&gt;</description>
      <pubDate>Thu, 10 Jun 2021 09:15:57 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00157.html</guid>
   </item>
    <item>
      <title>CVE-2020-35452: mod_auth_digest possible stack overflow by one nul byte</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00156.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2021/06/10&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Christophe JAILLET%22&quot;&gt;Christophe JAILLET&lt;/a&gt;</description>
      <pubDate>Thu, 10 Jun 2021 09:13:15 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00156.html</guid>
   </item>
    <item>
      <title>CVE-2020-13950: mod_proxy_http NULL pointer dereference</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00155.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2021/06/10&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Christophe JAILLET%22&quot;&gt;Christophe JAILLET&lt;/a&gt;</description>
      <pubDate>Thu, 10 Jun 2021 09:06:25 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00155.html</guid>
   </item>
    <item>
      <title>CVE-2020-13938: Improper Handling of Insufficient Privileges</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00154.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2021/06/10&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Christophe JAILLET%22&quot;&gt;Christophe JAILLET&lt;/a&gt;</description>
      <pubDate>Thu, 10 Jun 2021 09:01:12 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00154.html</guid>
   </item>
    <item>
      <title>CVE-2019-17567: mod_proxy_wstunnel tunneling of non Upgraded connections</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00153.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2021/06/10&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Christophe JAILLET%22&quot;&gt;Christophe JAILLET&lt;/a&gt;</description>
      <pubDate>Thu, 10 Jun 2021 08:59:43 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00153.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.48 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00152.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2021/06/02&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Christophe JAILLET%22&quot;&gt;Christophe JAILLET&lt;/a&gt;</description>
      <pubDate>Wed, 02 Jun 2021 04:19:43 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00152.html</guid>
   </item>
    <item>
      <title>[ANNOUNCE] libapreq2-2.16 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00151.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2021/03/22&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22jorton%22&quot;&gt;jorton&lt;/a&gt;</description>
      <pubDate>Mon, 22 Mar 2021 15:50:18 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00151.html</guid>
   </item>
    <item>
      <title>CVE-2020-9490: Push Diary Crash on Specifically Crafted HTTP/2 Header</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00150.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2020/08/07&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Fri, 07 Aug 2020 13:23:21 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00150.html</guid>
   </item>
    <item>
      <title>CVE-2020-11993: Push Diary Crash on Specifically Crafted HTTP/2 Header</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00149.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2020/08/07&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Fri, 07 Aug 2020 13:23:21 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00149.html</guid>
   </item>
    <item>
      <title>CVE-2020-11985: CWE-345: Insufficient verification of data authenticity</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00148.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2020/08/07&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Fri, 07 Aug 2020 13:20:20 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00148.html</guid>
   </item>
    <item>
      <title>CVE-2020-11984: mod_uwsgi buffer overlow</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00147.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2020/08/07&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Fri, 07 Aug 2020 13:19:25 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00147.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.46 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00146.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2020/08/07&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Fri, 07 Aug 2020 13:16:25 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00146.html</guid>
   </item>
    <item>
      <title>CVE-2019-9517: mod_http2, DoS attack by exhausting h2 workers</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00145.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2019/08/15&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Thu, 15 Aug 2019 03:59:51 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00145.html</guid>
   </item>
    <item>
      <title>CVE-2019-10098: mod_rewrite configurations vulnerable to open redirect</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00144.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2019/08/15&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Thu, 15 Aug 2019 03:58:20 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00144.html</guid>
   </item>
    <item>
      <title>CVE-2019-10097: mod_remoteip stack buffer overflow and NULL pointer dereference</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00143.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2019/08/15&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Thu, 15 Aug 2019 03:57:50 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00143.html</guid>
   </item>
    <item>
      <title>CVE-2019-10092: Limited cross-site scripting in mod_proxy</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00142.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2019/08/15&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Thu, 15 Aug 2019 03:57:49 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00142.html</guid>
   </item>
    <item>
      <title>CVE-2019-10082: mod_http2, read-after-free in h2 connection shutdown</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00141.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2019/08/15&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Thu, 15 Aug 2019 03:56:37 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00141.html</guid>
   </item>
    <item>
      <title>CVE-2019-10081: mod_http2, memory corruption on early pushes</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00140.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2019/08/15&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Thu, 15 Aug 2019 03:55:49 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00140.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.41 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00139.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2019/08/15&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Thu, 15 Aug 2019 03:54:47 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00139.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.39 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00138.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2019/04/02&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Tue, 02 Apr 2019 13:56:26 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00138.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.38 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00137.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2019/01/22&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Tue, 22 Jan 2019 17:31:07 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00137.html</guid>
   </item>
    <item>
      <title>CVE-2019-0190: mod_ssl 2.4.37 remote DoS when used with OpenSSL 1.1.1</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00136.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2019/01/22&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Tue, 22 Jan 2019 17:29:25 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00136.html</guid>
   </item>
    <item>
      <title>CVE-2018-17199: mod_session_cookie does not respect expiry time</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00135.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2019/01/22&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Tue, 22 Jan 2019 17:28:34 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00135.html</guid>
   </item>
    <item>
      <title>CVE-2018-17189: mod_http2, DoS via slow, unneeded request bodies</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00134.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2019/01/22&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Tue, 22 Jan 2019 17:27:42 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00134.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.37 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00133.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2018/10/23&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Tue, 23 Oct 2018 13:12:01 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00133.html</guid>
   </item>
    <item>
      <title>CVE-2018-11763: mod_http2, DoS via continuous SETTINGS frames</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00132.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2018/09/25&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Tue, 25 Sep 2018 14:07:46 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00132.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.35 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00131.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2018/09/25&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Tue, 25 Sep 2018 14:06:38 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00131.html</guid>
   </item>
    <item>
      <title>CVE-2018-8011: Apache HTTP Server mod_md DoS</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00130.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2018/07/18&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Mark Cox%22&quot;&gt;Mark Cox&lt;/a&gt;</description>
      <pubDate>Wed, 18 Jul 2018 15:01:29 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00130.html</guid>
   </item>
    <item>
      <title>CVE-2018-1333: Apache HTTP Server HTTP/2 DoS</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00129.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2018/07/18&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Mark Cox%22&quot;&gt;Mark Cox&lt;/a&gt;</description>
      <pubDate>Wed, 18 Jul 2018 14:59:57 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00129.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.34 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00128.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2018/07/16&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Jim Jagielski%22&quot;&gt;Jim Jagielski&lt;/a&gt;</description>
      <pubDate>Mon, 16 Jul 2018 16:06:36 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00128.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.33 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00127.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2018/03/26&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Mon, 26 Mar 2018 15:40:44 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00127.html</guid>
   </item>
    <item>
      <title>CVE-2018-1303: Possible out of bound read in mod_cache_socache</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00126.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2018/03/26&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Mon, 26 Mar 2018 15:39:07 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00126.html</guid>
   </item>
    <item>
      <title>CVE-2018-1301: Possible out of bound access after failure in reading the HTTP request</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00125.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2018/03/26&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Mon, 26 Mar 2018 15:38:28 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00125.html</guid>
   </item>
    <item>
      <title>CVE-2018-1312: Weak Digest auth nonce generation in mod_auth_digest</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00124.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2018/03/26&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Mon, 26 Mar 2018 15:37:27 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00124.html</guid>
   </item>
    <item>
      <title>CVE-2018-1283: Tampering of mod_session data for CGI applications</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00123.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2018/03/26&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Mon, 26 Mar 2018 15:36:07 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00123.html</guid>
   </item>
    <item>
      <title>CVE-2017-15715: &lt;FilesMatch&gt; bypass with a trailing newline in the file name</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00122.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2018/03/26&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Mon, 26 Mar 2018 15:35:01 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00122.html</guid>
   </item>
    <item>
      <title>CVE-2018-1302: Possible write of after free on HTTP/2 stream shutdown</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00121.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2018/03/26&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Mon, 26 Mar 2018 15:34:04 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00121.html</guid>
   </item>
    <item>
      <title>CVE-2017-15710: Out of bound write in mod_authnz_ldap when using too small Accept-Language values</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00120.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2018/03/26&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Daniel Ruggeri%22&quot;&gt;Daniel Ruggeri&lt;/a&gt;</description>
      <pubDate>Mon, 26 Mar 2018 15:33:07 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00120.html</guid>
   </item>
    <item>
      <title>[ANNOUNCE] Apache HTTP Server 2.4.29 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00119.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2017/10/23&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Jim Jagielski%22&quot;&gt;Jim Jagielski&lt;/a&gt;</description>
      <pubDate>Mon, 23 Oct 2017 16:58:25 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00119.html</guid>
   </item>
    <item>
      <title>[Announcement] Apache HTTP Server 2.4.28 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00118.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2017/10/05&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22William A Rowe Jr%22&quot;&gt;William A Rowe Jr&lt;/a&gt;</description>
      <pubDate>Thu, 05 Oct 2017 18:50:38 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00118.html</guid>
   </item>
    <item>
      <title>CVE-2017-9788: Uninitialized memory reflection in mod_auth_digest</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00117.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2017/07/13&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22William A Rowe Jr%22&quot;&gt;William A Rowe Jr&lt;/a&gt;</description>
      <pubDate>Thu, 13 Jul 2017 13:04:25 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00117.html</guid>
   </item>
    <item>
      <title>CVE-2017-9789: Apache httpd 2.4 Read after free in mod_http2</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00116.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2017/07/13&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22William A Rowe Jr%22&quot;&gt;William A Rowe Jr&lt;/a&gt;</description>
      <pubDate>Thu, 13 Jul 2017 13:02:38 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00116.html</guid>
   </item>
    <item>
      <title>[Announcement] Apache HTTP Server 2.2.34 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00115.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2017/07/11&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22William A Rowe Jr%22&quot;&gt;William A Rowe Jr&lt;/a&gt;</description>
      <pubDate>Tue, 11 Jul 2017 19:13:49 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00115.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.27 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00114.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2017/07/11&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Jim Jagielski%22&quot;&gt;Jim Jagielski&lt;/a&gt;</description>
      <pubDate>Tue, 11 Jul 2017 13:13:30 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00114.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2017-7679: mod_mime buffer overread</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00113.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2017/06/19&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Jacob Champion%22&quot;&gt;Jacob Champion&lt;/a&gt;</description>
      <pubDate>Mon, 19 Jun 2017 22:54:24 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00113.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2017-7668: ap_find_token buffer overread</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00112.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2017/06/19&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Jacob Champion%22&quot;&gt;Jacob Champion&lt;/a&gt;</description>
      <pubDate>Mon, 19 Jun 2017 22:53:22 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00112.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2017-7659: mod_http2 null pointer dereference</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00111.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2017/06/19&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Jacob Champion%22&quot;&gt;Jacob Champion&lt;/a&gt;</description>
      <pubDate>Mon, 19 Jun 2017 22:53:22 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00111.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2017-3169: mod_ssl null pointer dereference</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00110.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2017/06/19&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Jacob Champion%22&quot;&gt;Jacob Champion&lt;/a&gt;</description>
      <pubDate>Mon, 19 Jun 2017 22:51:34 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00110.html</guid>
   </item>
    <item>
      <title>[SECURITY] CVE-2017-3167: ap_get_basic_auth_pw authentication bypass</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00109.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2017/06/19&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Jacob Champion%22&quot;&gt;Jacob Champion&lt;/a&gt;</description>
      <pubDate>Mon, 19 Jun 2017 22:50:39 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00109.html</guid>
   </item>
    <item>
      <title>[ANNOUNCE] Apache HTTP Server 2.4.26 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00108.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2017/06/19&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Jim Jagielski%22&quot;&gt;Jim Jagielski&lt;/a&gt;</description>
      <pubDate>Mon, 19 Jun 2017 13:04:03 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00108.html</guid>
   </item>
    <item>
      <title>[ANNOUNCE] Apache HTTP Server 2.4.25 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00107.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2016/12/20&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Jacob Champion%22&quot;&gt;Jacob Champion&lt;/a&gt;</description>
      <pubDate>Tue, 20 Dec 2016 20:25:06 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00107.html</guid>
   </item>
    <item>
      <title>CVE-2016-8740, Server memory can be exhausted and service denied when HTTP/2 is used</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00106.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2016/12/05&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22icing%22&quot;&gt;icing&lt;/a&gt;</description>
      <pubDate>Mon, 05 Dec 2016 17:32:08 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00106.html</guid>
   </item>
    <item>
      <title>CVE-2016-4979: HTTPD webserver - X509 Client certificate based authentication can be bypassed when HTTP/2 is used [vs]</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00105.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2016/07/05&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Dirk-Willem van Gulik%22&quot;&gt;Dirk-Willem van Gulik&lt;/a&gt;</description>
      <pubDate>Tue, 05 Jul 2016 15:02:38 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00105.html</guid>
   </item>
    <item>
      <title>[ANNOUNCE] Apache HTTP Server 2.4.23 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00104.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2016/07/05&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Jim Jagielski%22&quot;&gt;Jim Jagielski&lt;/a&gt;</description>
      <pubDate>Tue, 05 Jul 2016 13:09:14 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00104.html</guid>
   </item>
    <item>
      <title>[ANNOUNCE] Apache HTTP Server 2.4.20 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00103.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2016/04/11&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Jim Jagielski%22&quot;&gt;Jim Jagielski&lt;/a&gt;</description>
      <pubDate>Mon, 11 Apr 2016 13:35:41 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00103.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.18 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00102.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2015/12/22&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Jim Jagielski%22&quot;&gt;Jim Jagielski&lt;/a&gt;</description>
      <pubDate>Tue, 22 Dec 2015 21:05:57 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00102.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.18 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00101.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2015/12/14&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Jim Jagielski%22&quot;&gt;Jim Jagielski&lt;/a&gt;</description>
      <pubDate>Mon, 14 Dec 2015 20:42:06 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00101.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT]  Apache HTTP Server 2.4.17 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00100.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2015/10/13&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Jim Jagielski%22&quot;&gt;Jim Jagielski&lt;/a&gt;</description>
      <pubDate>Tue, 13 Oct 2015 18:18:34 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00100.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.16 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00099.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2015/07/16&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Jim Jagielski%22&quot;&gt;Jim Jagielski&lt;/a&gt;</description>
      <pubDate>Thu, 16 Jul 2015 11:44:58 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00099.html</guid>
   </item>
    <item>
      <title>[Announce] Apache HTTP Server 2.2.29 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00098.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2014/09/03&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22William A. Rowe Jr.%22&quot;&gt;William A. Rowe Jr.&lt;/a&gt;</description>
      <pubDate>Wed, 03 Sep 2014 15:50:51 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00098.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server 2.4.10 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00097.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2014/07/21&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Jim Jagielski%22&quot;&gt;Jim Jagielski&lt;/a&gt;</description>
      <pubDate>Mon, 21 Jul 2014 15:09:28 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00097.html</guid>
   </item>
    <item>
      <title>[Announcment] Apache HTTP Server 2.2.27 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00096.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2014/03/26&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22William A. Rowe Jr.%22&quot;&gt;William A. Rowe Jr.&lt;/a&gt;</description>
      <pubDate>Wed, 26 Mar 2014 22:01:29 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00096.html</guid>
   </item>
    <item>
      <title>ANNOUNCE: Apache HTTP Server 2.4.9 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00095.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2014/03/17&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Jim Jagielski%22&quot;&gt;Jim Jagielski&lt;/a&gt;</description>
      <pubDate>Mon, 17 Mar 2014 20:20:31 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00095.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server (httpd) 2.4.7 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00094.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2013/11/26&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Jim Jagielski%22&quot;&gt;Jim Jagielski&lt;/a&gt;</description>
      <pubDate>Tue, 26 Nov 2013 19:36:02 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00094.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server (httpd) 2.2.26 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00093.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2013/11/18&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Jim Jagielski%22&quot;&gt;Jim Jagielski&lt;/a&gt;</description>
      <pubDate>Mon, 18 Nov 2013 18:44:19 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00093.html</guid>
   </item>
    <item>
      <title>[ANNOUNCEMENT] Apache HTTP Server (httpd) 2.4.6 Released</title>
      <link>http://www.mail-archive.com/announce@httpd.apache.org/msg00092.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2013/07/22&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=announce@httpd.apache.org&amp;q=from:%22Jim Jagielski%22&quot;&gt;Jim Jagielski&lt;/a&gt;</description>
      <pubDate>Mon, 22 Jul 2013 15:02:12 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/announce@httpd.apache.org/msg00092.html</guid>
   </item>
 
  </channel>
  </rss>
<!-- MHonArc v2.6.19+ -->
