CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

USN-8589-1: Apache HTTP Server vulnerabilities

unknownCVE-2026-29167CVE-2026-29170CVE-2026-33006
It was discovered that Apache HTTP Server's mod_ldap module incorrectly handled memory when processing per-directory configurations. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-29167) It was discovered that Apache HTTP Server's mod_proxy_ftp module incorrectly handled HTML generation for FTP directory listings. A remote attacker could possibly use this issue to inject arbitrary web script or HTML. (CVE-2026-29170) Nitescu Lucian discovered that Apache HTTP Server's mod_auth_digest module was vulnerable to a timing attack. A remote attacker could possibly use this issue to bypass Digest authentication. (CVE-2026-33006)

CSIRTS triage

What
Apache HTTP Server has vulnerabilities in its modules that could allow remote code execution, denial of service, or authentication bypass.
Who is affected
Deployments of Apache HTTP Server with the affected modules.
Urgency
Remediation is urgent due to the potential for remote code execution and denial of service.
Action
Apply the latest patches for Apache HTTP Server.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Apache HTTP Server

Get an email when a new Apache HTTP Server advisory drops — max one per day, one-click unsubscribe.

Details

Source
Ubuntu Security Notices (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-07-22
Exploitation
Not in CISA KEV at last sync

Original advisory: https://ubuntu.com/security/notices/USN-8589-1

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-29167coverage & exploitation statusNVD · CVE.org
CVE-2026-29170coverage & exploitation statusNVD · CVE.org
CVE-2026-33006coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Ubuntu Security Notices