{
  "from_raw": "Eric Covener <covener@apache.org>",
  "from": "Eric Covener <co...@apache.org>",
  "gravatar": "ee9bd44fca004cd144fce0d972679406",
  "to": "an...@apache.org,\n an...@httpd.apache.org",
  "subject": "CVE-2026-79768: Apache HTTP Server: mod_userdir information disclosure",
  "message-id": "<c63a576d-8fb9-675f-9f7d-daa86e906c00@apache.org>",
  "mid": "63wmzs4y1p3mjo7t8cqwjp8kdt65x055",
  "permalinks": [
    "63wmzs4y1p3mjo7t8cqwjp8kdt65x055",
    "r5ed821757741cd63f7f5009bebea1e662e2a13397fe5f5a325ec76d4@<announce.apache.org>"
  ],
  "dbid": "14b072f2f66bd9ed97bc055ac6631799927ff280e4dfe45ef3f4ab8410648cd5",
  "cc": "an...@httpd.apache.org",
  "epoch": 1790878173,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/10/01 18:09:33",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: low \n\nAffected versions:\n\n- Apache HTTP Server 2.4.0 through 2.4.68\n\nDescription:\n\nPath equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with\u00a0absolute non-wildcard UserDir directive (the 2nd form in\u00a0https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir)\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.\n\nCredit:\n\nVlatko Kosturjak, Marlink Cyber (finder)\n\nReferences:\n\nhttps://httpd.apache.org/security/vulnerabilities_24.html\nhttps://httpd.apache.org/\nhttps://www.cve.org/CVERecord?id=CVE-2026-79768\n\nTimeline:\n\n2026-08-14: reported\n2026-10-01: fixed in 2.4.x by r1938680\n2026-10-01: 2.4.69 released\n\n",
  "body_short": "Severity: low \n\nAffected versions:\n\n- Apache HTTP Server 2.4.0 through 2.4.68\n\nDescription:\n\nPath equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 3330,
  "id": "63wmzs4y1p3mjo7t8cqwjp8kdt65x055"
}