{
  "document": {
    "aggregate_severity": {
      "text": "Moderate"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "CVE-2025-65082: fix CGI environment variable injection by preventing HTTP\n  headers from overriding server-set variables and added regression tests\n- CVE-2025-66200: prevent suexec bypass by removing request notes usage and rejecting\n  the undocumented RequestHeader note option",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/tuxcare9.6esu/advisories/2026/clsa-2026_1769099972.json"
      },
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1769099972",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1769099972"
      }
    ],
    "tracking": {
      "current_release_date": "2026-01-22T16:40:23Z",
      "generator": {
        "date": "2026-01-22T16:40:23Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1769099972",
      "initial_release_date": "2026-01-22T16:40:23Z",
      "revision_history": [
        {
          "date": "2026-01-22T16:40:23Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "httpd: Fix of 2 CVEs"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "AlmaLinux 9.6",
                "product": {
                  "name": "AlmaLinux 9.6",
                  "product_id": "AlmaLinux-9.6",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:almalinux:almalinux:9.6:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "AlmaLinux"
          }
        ],
        "category": "vendor",
        "name": "AlmaLinux OS Foundation"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Rocky Linux 9.6",
                "product": {
                  "name": "Rocky Linux 9.6",
                  "product_id": "Rocky Linux-9.6",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:resf:rocky_linux:9.6:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Rocky Linux"
          }
        ],
        "category": "vendor",
        "name": "Rocky Linux"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "mod_ldap-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                "product": {
                  "name": "mod_ldap-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                  "product_id": "mod_ldap-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/mod_ldap@2.4.62-4.el9_6.4.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "httpd-devel-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                "product": {
                  "name": "httpd-devel-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                  "product_id": "httpd-devel-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/httpd-devel@2.4.62-4.el9_6.4.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mod_session-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                "product": {
                  "name": "mod_session-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                  "product_id": "mod_session-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/mod_session@2.4.62-4.el9_6.4.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "httpd-tools-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                "product": {
                  "name": "httpd-tools-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                  "product_id": "httpd-tools-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/httpd-tools@2.4.62-4.el9_6.4.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "httpd-core-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                "product": {
                  "name": "httpd-core-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                  "product_id": "httpd-core-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/httpd-core@2.4.62-4.el9_6.4.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mod_lua-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                "product": {
                  "name": "mod_lua-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                  "product_id": "mod_lua-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/mod_lua@2.4.62-4.el9_6.4.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mod_proxy_html-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                "product": {
                  "name": "mod_proxy_html-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                  "product_id": "mod_proxy_html-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/mod_proxy_html@2.4.62-4.el9_6.4.tuxcare.els2?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mod_ssl-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                "product": {
                  "name": "mod_ssl-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                  "product_id": "mod_ssl-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/mod_ssl@2.4.62-4.el9_6.4.tuxcare.els2?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "httpd-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                "product": {
                  "name": "httpd-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                  "product_id": "httpd-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/httpd@2.4.62-4.el9_6.4.tuxcare.els2?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "httpd-filesystem-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
                "product": {
                  "name": "httpd-filesystem-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
                  "product_id": "httpd-filesystem-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/httpd-filesystem@2.4.62-4.el9_6.4.tuxcare.els2?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "httpd-manual-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
                "product": {
                  "name": "httpd-manual-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
                  "product_id": "httpd-manual-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/httpd-manual@2.4.62-4.el9_6.4.tuxcare.els2?arch=noarch"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mod_ldap-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64 as a component of AlmaLinux 9.6",
          "product_id": "AlmaLinux-9.6:mod_ldap-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
        },
        "product_reference": "mod_ldap-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "httpd-devel-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64 as a component of AlmaLinux 9.6",
          "product_id": "AlmaLinux-9.6:httpd-devel-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
        },
        "product_reference": "httpd-devel-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mod_session-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64 as a component of AlmaLinux 9.6",
          "product_id": "AlmaLinux-9.6:mod_session-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
        },
        "product_reference": "mod_session-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "httpd-filesystem-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch as a component of AlmaLinux 9.6",
          "product_id": "AlmaLinux-9.6:httpd-filesystem-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch"
        },
        "product_reference": "httpd-filesystem-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
        "relates_to_product_reference": "AlmaLinux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "httpd-tools-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64 as a component of AlmaLinux 9.6",
          "product_id": "AlmaLinux-9.6:httpd-tools-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
        },
        "product_reference": "httpd-tools-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "httpd-core-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64 as a component of AlmaLinux 9.6",
          "product_id": "AlmaLinux-9.6:httpd-core-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
        },
        "product_reference": "httpd-core-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mod_lua-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64 as a component of AlmaLinux 9.6",
          "product_id": "AlmaLinux-9.6:mod_lua-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
        },
        "product_reference": "mod_lua-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mod_proxy_html-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64 as a component of AlmaLinux 9.6",
          "product_id": "AlmaLinux-9.6:mod_proxy_html-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
        },
        "product_reference": "mod_proxy_html-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "httpd-manual-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch as a component of AlmaLinux 9.6",
          "product_id": "AlmaLinux-9.6:httpd-manual-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch"
        },
        "product_reference": "httpd-manual-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
        "relates_to_product_reference": "AlmaLinux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mod_ssl-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64 as a component of AlmaLinux 9.6",
          "product_id": "AlmaLinux-9.6:mod_ssl-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
        },
        "product_reference": "mod_ssl-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "httpd-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64 as a component of AlmaLinux 9.6",
          "product_id": "AlmaLinux-9.6:httpd-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
        },
        "product_reference": "httpd-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mod_ldap-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64 as a component of Rocky Linux 9.6",
          "product_id": "Rocky Linux-9.6:mod_ldap-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
        },
        "product_reference": "mod_ldap-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
        "relates_to_product_reference": "Rocky Linux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "httpd-devel-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64 as a component of Rocky Linux 9.6",
          "product_id": "Rocky Linux-9.6:httpd-devel-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
        },
        "product_reference": "httpd-devel-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
        "relates_to_product_reference": "Rocky Linux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mod_session-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64 as a component of Rocky Linux 9.6",
          "product_id": "Rocky Linux-9.6:mod_session-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
        },
        "product_reference": "mod_session-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
        "relates_to_product_reference": "Rocky Linux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "httpd-filesystem-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch as a component of Rocky Linux 9.6",
          "product_id": "Rocky Linux-9.6:httpd-filesystem-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch"
        },
        "product_reference": "httpd-filesystem-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
        "relates_to_product_reference": "Rocky Linux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "httpd-tools-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64 as a component of Rocky Linux 9.6",
          "product_id": "Rocky Linux-9.6:httpd-tools-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
        },
        "product_reference": "httpd-tools-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
        "relates_to_product_reference": "Rocky Linux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "httpd-core-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64 as a component of Rocky Linux 9.6",
          "product_id": "Rocky Linux-9.6:httpd-core-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
        },
        "product_reference": "httpd-core-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
        "relates_to_product_reference": "Rocky Linux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mod_lua-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64 as a component of Rocky Linux 9.6",
          "product_id": "Rocky Linux-9.6:mod_lua-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
        },
        "product_reference": "mod_lua-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
        "relates_to_product_reference": "Rocky Linux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mod_proxy_html-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64 as a component of Rocky Linux 9.6",
          "product_id": "Rocky Linux-9.6:mod_proxy_html-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
        },
        "product_reference": "mod_proxy_html-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
        "relates_to_product_reference": "Rocky Linux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "httpd-manual-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch as a component of Rocky Linux 9.6",
          "product_id": "Rocky Linux-9.6:httpd-manual-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch"
        },
        "product_reference": "httpd-manual-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
        "relates_to_product_reference": "Rocky Linux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mod_ssl-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64 as a component of Rocky Linux 9.6",
          "product_id": "Rocky Linux-9.6:mod_ssl-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
        },
        "product_reference": "mod_ssl-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
        "relates_to_product_reference": "Rocky Linux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "httpd-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64 as a component of Rocky Linux 9.6",
          "product_id": "Rocky Linux-9.6:httpd-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
        },
        "product_reference": "httpd-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
        "relates_to_product_reference": "Rocky Linux-9.6"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-65082",
      "cwe": {
        "id": "CWE-150",
        "name": "Improper Neutralization of Escape, Meta, or Control Sequences"
      },
      "notes": [
        {
          "category": "description",
          "text": "Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs.\nThis issue affects Apache HTTP Server from 2.4.0 through 2.4.65.\nUsers are recommended to upgrade to version 2.4.66 which fixes the issue.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.6:httpd-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "AlmaLinux-9.6:httpd-core-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "AlmaLinux-9.6:httpd-devel-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "AlmaLinux-9.6:httpd-filesystem-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
          "AlmaLinux-9.6:httpd-manual-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
          "AlmaLinux-9.6:httpd-tools-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "AlmaLinux-9.6:mod_ldap-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "AlmaLinux-9.6:mod_lua-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "AlmaLinux-9.6:mod_proxy_html-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "AlmaLinux-9.6:mod_session-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "AlmaLinux-9.6:mod_ssl-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "Rocky Linux-9.6:httpd-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "Rocky Linux-9.6:httpd-core-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "Rocky Linux-9.6:httpd-devel-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "Rocky Linux-9.6:httpd-filesystem-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
          "Rocky Linux-9.6:httpd-manual-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
          "Rocky Linux-9.6:httpd-tools-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "Rocky Linux-9.6:mod_ldap-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "Rocky Linux-9.6:mod_lua-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "Rocky Linux-9.6:mod_proxy_html-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "Rocky Linux-9.6:mod_session-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "Rocky Linux-9.6:mod_ssl-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-65082"
        }
      ],
      "release_date": "2025-12-05T10:46:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-01-22T16:39:34.023429Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1769099972",
          "product_ids": [
            "AlmaLinux-9.6:httpd-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:httpd-core-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:httpd-devel-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:httpd-filesystem-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
            "AlmaLinux-9.6:httpd-manual-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
            "AlmaLinux-9.6:httpd-tools-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:mod_ldap-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:mod_lua-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:mod_proxy_html-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:mod_session-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:mod_ssl-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:httpd-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:httpd-core-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:httpd-devel-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:httpd-filesystem-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
            "Rocky Linux-9.6:httpd-manual-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
            "Rocky Linux-9.6:httpd-tools-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:mod_ldap-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:mod_lua-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:mod_proxy_html-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:mod_session-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:mod_ssl-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1769099972"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "AlmaLinux-9.6:httpd-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:httpd-core-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:httpd-devel-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:httpd-filesystem-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
            "AlmaLinux-9.6:httpd-manual-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
            "AlmaLinux-9.6:httpd-tools-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:mod_ldap-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:mod_lua-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:mod_proxy_html-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:mod_session-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:mod_ssl-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:httpd-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:httpd-core-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:httpd-devel-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:httpd-filesystem-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
            "Rocky Linux-9.6:httpd-manual-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
            "Rocky Linux-9.6:httpd-tools-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:mod_ldap-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:mod_lua-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:mod_proxy_html-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:mod_session-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:mod_ssl-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2025-66200",
      "cwe": {
        "id": "CWE-305",
        "name": "Authentication Bypass by Primary Weakness"
      },
      "notes": [
        {
          "category": "description",
          "text": "mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid.\nThis issue affects Apache HTTP Server: from 2.4.7 through 2.4.65.\nUsers are recommended to upgrade to version 2.4.66, which fixes the issue.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.6:httpd-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "AlmaLinux-9.6:httpd-core-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "AlmaLinux-9.6:httpd-devel-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "AlmaLinux-9.6:httpd-filesystem-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
          "AlmaLinux-9.6:httpd-manual-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
          "AlmaLinux-9.6:httpd-tools-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "AlmaLinux-9.6:mod_ldap-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "AlmaLinux-9.6:mod_lua-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "AlmaLinux-9.6:mod_proxy_html-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "AlmaLinux-9.6:mod_session-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "AlmaLinux-9.6:mod_ssl-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "Rocky Linux-9.6:httpd-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "Rocky Linux-9.6:httpd-core-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "Rocky Linux-9.6:httpd-devel-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "Rocky Linux-9.6:httpd-filesystem-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
          "Rocky Linux-9.6:httpd-manual-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
          "Rocky Linux-9.6:httpd-tools-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "Rocky Linux-9.6:mod_ldap-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "Rocky Linux-9.6:mod_lua-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "Rocky Linux-9.6:mod_proxy_html-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "Rocky Linux-9.6:mod_session-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
          "Rocky Linux-9.6:mod_ssl-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-66200"
        }
      ],
      "release_date": "2025-12-05T11:02:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-01-22T16:39:34.023429Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1769099972",
          "product_ids": [
            "AlmaLinux-9.6:httpd-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:httpd-core-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:httpd-devel-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:httpd-filesystem-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
            "AlmaLinux-9.6:httpd-manual-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
            "AlmaLinux-9.6:httpd-tools-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:mod_ldap-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:mod_lua-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:mod_proxy_html-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:mod_session-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:mod_ssl-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:httpd-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:httpd-core-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:httpd-devel-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:httpd-filesystem-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
            "Rocky Linux-9.6:httpd-manual-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
            "Rocky Linux-9.6:httpd-tools-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:mod_ldap-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:mod_lua-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:mod_proxy_html-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:mod_session-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:mod_ssl-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1769099972"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "AlmaLinux-9.6:httpd-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:httpd-core-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:httpd-devel-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:httpd-filesystem-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
            "AlmaLinux-9.6:httpd-manual-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
            "AlmaLinux-9.6:httpd-tools-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:mod_ldap-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:mod_lua-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:mod_proxy_html-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:mod_session-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "AlmaLinux-9.6:mod_ssl-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:httpd-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:httpd-core-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:httpd-devel-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:httpd-filesystem-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
            "Rocky Linux-9.6:httpd-manual-0:2.4.62-4.el9_6.4.tuxcare.els2.noarch",
            "Rocky Linux-9.6:httpd-tools-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:mod_ldap-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:mod_lua-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:mod_proxy_html-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:mod_session-0:2.4.62-4.el9_6.4.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:mod_ssl-1:2.4.62-4.el9_6.4.tuxcare.els2.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}