{
  "from_raw": "Eric Covener <covener@apache.org>",
  "from": "Eric Covener <co...@apache.org>",
  "gravatar": "ee9bd44fca004cd144fce0d972679406",
  "to": "an...@apache.org,\n de...@httpd.apache.org",
  "subject": "CVE-2026-59797: Apache HTTP Server: mod_ssl SSLRequire allows .htaccess ap_expr file-function",
  "message-id": "<f272524f-c303-e024-35cb-b1d1fb7c765d@apache.org>",
  "mid": "hqgds2nmsf3rkhwhp5g0b93wwq3jd2c9",
  "permalinks": [
    "hqgds2nmsf3rkhwhp5g0b93wwq3jd2c9",
    "rc5f73ffb7b7030682908f3652f026ef3eb3319a123ad41cd794ba5ed@<dev.httpd.apache.org>"
  ],
  "dbid": "0b958393540c430f606e9c625d55fa3e3d22f4d70fed07195d1bc8041ac3cf39",
  "cc": "",
  "epoch": 1790878060,
  "list": "<dev.httpd.apache.org>",
  "list_raw": "<dev.httpd.apache.org>",
  "date": "2026/10/01 18:07:40",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: low \n\nAffected versions:\n\n- Apache HTTP Server 2.4.0 through 2.4.68\n\nDescription:\n\nImproper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.\n\nCredit:\n\nkimchunbok (finder)\nl1nx1n (finder)\nJuthawong Naisanguansee (finder)\nCharles Vosburgh (finder)\nMike Read (finder)\nRyoma Nishioka (finder)\n\nReferences:\n\nhttps://httpd.apache.org/security/vulnerabilities_24.html\nhttps://httpd.apache.org/\nhttps://www.cve.org/CVERecord?id=CVE-2026-59797\n\nTimeline:\n\n2026-06-28: reported\n2026-10-01: fixed in 2.4.x by r1938672\n2026-10-01: 2.4.69 released\n\n",
  "body_short": "Severity: low \n\nAffected versions:\n\n- Apache HTTP Server 2.4.0 through 2.4.68\n\nDescription:\n\nImproper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related ",
  "html_source_only": false,
  "attachments": [],
  "forum": "dev@httpd.apache.org",
  "size": 3851,
  "id": "hqgds2nmsf3rkhwhp5g0b93wwq3jd2c9"
}