Datos actualizados a diario

Avisos de seguridad

Vulnerabilidades publicadas recientemente en el software que administramos a diario. La lista está filtrada: solo aparece lo que afecta a servidores en producción, no el catálogo completo de CVE.

3 crítica 22 alta 21 media 4 baja 57 vulnerabilidades · últimos 30 días · actualizado el 2026-10-05
CVE Severidad Software Resumen Corregido en Publicado
CVE-2026-56154 Crítica 9.8 Apache HTTP Server Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0… Debian:14: 2.4.69-1 2026-10-01
CVE-2026-57941 Crítica 9.8 Apache HTTP Server Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0… Debian:14: 2.4.69-1 2026-10-01
CVE-2026-59797 Crítica 9.8 Apache HTTP Server Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP… Debian:14: 2.4.69-1 2026-10-01
CVE-2026-46729 Alta 7.5 Apache HTTP Server NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0… Debian:14: 2.4.69-1 2026-10-01
CVE-2026-47360 Alta 7.5 Apache HTTP Server Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.   When SessionCookieRemove… Debian:14: 2.4.69-1 2026-10-01
CVE-2026-48005 Alta 7.5 Apache HTTP Server Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated… Debian:14: 2.4.69-1 2026-10-01
CVE-2026-56153 Alta 7.5 Apache HTTP Server Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. Debian:14: 2.4.69-1 2026-10-01
CVE-2026-56449 Alta 7.5 Apache HTTP Server Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from… Debian:14: 2.4.69-1 2026-10-01
CVE-2026-59685 Alta 7.5 Apache HTTP Server Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache… Sin parche aún 2026-10-01
CVE-2026-63045 Alta 7.5 Apache HTTP Server Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in… Debian:14: 2.4.69-1 2026-10-01
CVE-2026-63292 Alta 7.5 Apache HTTP Server Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause… Debian:14: 2.4.69-1 2026-10-01
CVE-2026-63686 Alta 7.5 Apache HTTP Server A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to… Debian:14: 2.4.69-1 2026-10-01
CVE-2026-63718 Alta 7.5 Apache HTTP Server Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and… Debian:14: 2.4.69-1 2026-10-01
CVE-2026-73636 Alta 8.1 Apache HTTP Server Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle… Debian:14: 2.4.69-1 2026-10-01
CVE-2026-73637 Alta 7.3 Apache HTTP Server Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to… Debian:14: 2.4.69-1 2026-10-01
CVE-2026-93546 Alta 8.8 Apache HTTP Server Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and… Debian:14: 2.4.69-1 2026-10-01
CVE-2026-84782 Alta 8.2 OpenSSL Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message… Debian:13: 3.5.7-1~deb13u3
Ubuntu:14.04: 1.0.1f-1ubuntu2.27+esm17
Ubuntu:16.04: 1.0.2g-1ubuntu4.20+esm19
Ubuntu:18.04: 1.1.1-1ubuntu2.1~18.04.23+esm11
Ubuntu:20.04: 1.1.1f-1ubuntu2.24+esm6
Ubuntu:22.04: 3.0.2-0ubuntu1.30
Ubuntu:24.04: 3.0.13-0ubuntu3.16
Ubuntu:26.04: 3.5.5-1ubuntu3.6
2026-09-29
CVE-2026-91765 Alta 7.5 PHP cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request… Debian:12: 8.2.34-1~deb12u1
Debian:13: 8.4.26-1~deb13u1
2026-09-25
CVE-2026-19666 Alta 7.5 BIND On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process… Debian:13: 1:9.20.29-1~deb13u1
Debian:14: 1:9.20.29-1
2026-09-16
CVE-2026-19667 Alta 7.5 BIND If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache… Debian:13: 1:9.20.29-1~deb13u1
Debian:14: 1:9.20.29-1
2026-09-16
CVE-2026-76163 Alta 7.5 BIND If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion… Debian:13: 1:9.20.29-1~deb13u1
Debian:14: 1:9.20.29-1
2026-09-16
CVE-2026-77692 Alta 7.5 BIND An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the… Debian:13: 1:9.20.29-1~deb13u1
Debian:14: 1:9.20.29-1
2026-09-16
CVE-2026-80274 Alta 7.5 BIND If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3… Debian:13: 1:9.20.29-1~deb13u1
Debian:14: 1:9.20.29-1
2026-09-16
CVE-2026-81563 Alta 7.5 BIND A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal… Debian:13: 1:9.20.29-1~deb13u1
Debian:14: 1:9.20.29-1
2026-09-16
CVE-2026-81736 Alta 7.5 BIND If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate… Debian:13: 1:9.20.29-1~deb13u1
Debian:14: 1:9.20.29-1
2026-09-16
CVE-2026-42528 Media 4.3 Apache HTTP Server A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child… Debian:14: 2.4.69-1 2026-10-01
CVE-2026-58415 Media 5.3 Apache HTTP Server Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a… Debian:14: 2.4.69-1 2026-10-01
CVE-2026-79768 Media 5.3 Apache HTTP Server Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir… Debian:14: 2.4.69-1 2026-10-01
CVE-2026-35189 Media 5.3 OpenSSL Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509… Debian:13: 3.5.7-1~deb13u3
Ubuntu:14.04: 1.0.1f-1ubuntu2.27+esm17
Ubuntu:16.04: 1.0.2g-1ubuntu4.20+esm19
Ubuntu:18.04: 1.1.1-1ubuntu2.1~18.04.23+esm11
Ubuntu:20.04: 1.1.1f-1ubuntu2.24+esm6
Ubuntu:22.04: 3.0.2-0ubuntu1.30
Ubuntu:24.04: 3.0.13-0ubuntu3.16
Ubuntu:26.04: 3.5.5-1ubuntu3.6
2026-09-29
CVE-2026-75805 Media 5.3 OpenSSL Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when… Debian:13: 3.5.7-1~deb13u3
Ubuntu:22.04: 3.0.2-0ubuntu1.30
Ubuntu:24.04: 3.0.13-0ubuntu3.16
Ubuntu:26.04: 3.5.5-1ubuntu3.6
2026-09-29
CVE-2026-75806 Media 5.3 OpenSSL Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment… Debian:13: 3.5.7-1~deb13u3
Ubuntu:22.04: 3.0.2-0ubuntu1.30
Ubuntu:24.04: 3.0.13-0ubuntu3.16
Ubuntu:26.04: 3.5.5-1ubuntu3.6
2026-09-29
CVE-2025-14181 Media 6.5 PHP The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed… Debian:12: 8.2.34-1~deb12u1
Debian:13: 8.4.26-1~deb13u1
2026-09-25
CVE-2026-6103 Media 4.3 PHP phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal digits wide and holds values up to… Debian:12: 8.2.34-1~deb12u1
Debian:13: 8.4.26-1~deb13u1
2026-09-25
CVE-2026-91766 Media 5.9 PHP When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the… Debian:12: 8.2.34-1~deb12u1
Debian:13: 8.4.26-1~deb13u1
2026-09-25
CVE-2026-91767 Media 6.5 PHP php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard… Debian:12: 8.2.34-1~deb12u1
Debian:13: 8.4.26-1~deb13u1
2026-09-25
CVE-2026-91768 Media 6.5 PHP The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96… Debian:12: 8.2.34-1~deb12u1
Debian:13: 8.4.26-1~deb13u1
2026-09-25
CVE-2026-91769 Media 4.3 PHP PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC… Debian:12: 8.2.34-1~deb12u1
Debian:13: 8.4.26-1~deb13u1
2026-09-25
CVE-2026-92842 Media 5.9 PHP The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is… Debian:12: 8.2.34-1~deb12u1
Debian:13: 8.4.26-1~deb13u1
2026-09-25
CVE-2026-93682 Media 5.8 PHP When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end… Debian:12: 8.2.34-1~deb12u1
Debian:13: 8.4.26-1~deb13u1
2026-09-25
CVE-2026-19033 Media 6.5 BIND For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG… Debian:13: 1:9.20.29-1~deb13u1
Debian:14: 1:9.20.29-1
2026-09-16
CVE-2026-19662 Media 5.9 BIND An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed… Debian:13: 1:9.20.29-1~deb13u1
Debian:14: 1:9.20.29-1
2026-09-16
CVE-2026-19668 Media 5.3 BIND A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default… Debian:13: 1:9.20.29-1~deb13u1
Debian:14: 1:9.20.29-1
2026-09-16
CVE-2026-19941 Media 5.9 BIND An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream… Debian:13: 1:9.20.29-1~deb13u1
Debian:14: 1:9.20.29-1
2026-09-16
CVE-2026-75029 Media 5.3 BIND In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on… Debian:13: 1:9.20.29-1~deb13u1
Debian:14: 1:9.20.29-1
2026-09-16
CVE-2026-77119 Media 5.9 BIND A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned… Debian:13: 1:9.20.29-1~deb13u1
Debian:14: 1:9.20.29-1
2026-09-16
CVE-2026-78301 Media 5.8 BIND A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND… Debian:13: 1:9.20.29-1~deb13u1
Debian:14: 1:9.20.29-1
2026-09-16
CVE-2026-42356 Baja 3.7 Apache HTTP Server Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and… Debian:14: 2.4.69-1 2026-10-01
CVE-2026-54872 Baja 3.7 OpenSSL Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated… Debian:13: 3.5.7-1~deb13u3
Ubuntu:14.04: 1.0.1f-1ubuntu2.27+esm17
Ubuntu:16.04: 1.0.2g-1ubuntu4.20+esm19
Ubuntu:18.04: 1.1.1-1ubuntu2.1~18.04.23+esm11
Ubuntu:20.04: 1.1.1f-1ubuntu2.24+esm6
Ubuntu:22.04: 3.0.2-0ubuntu1.30
Ubuntu:24.04: 3.0.13-0ubuntu3.16
Ubuntu:26.04: 3.5.5-1ubuntu3.6
2026-09-29
CVE-2026-77696 Baja 3.7 OpenSSL Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to… Debian:13: 3.5.7-1~deb13u3
Ubuntu:14.04: 1.0.1f-1ubuntu2.27+esm17
Ubuntu:16.04: 1.0.2g-1ubuntu4.20+esm19
Ubuntu:18.04: 1.1.1-1ubuntu2.1~18.04.23+esm11
Ubuntu:20.04: 1.1.1f-1ubuntu2.24+esm6
Ubuntu:22.04: 3.0.2-0ubuntu1.30
Ubuntu:24.04: 3.0.13-0ubuntu3.16
Ubuntu:26.04: 3.5.5-1ubuntu3.6
2026-09-29
CVE-2025-1218 Baja 3.4 PHP The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or… Debian:12: 8.2.34-1~deb12u1
Debian:13: 8.4.26-1~deb13u1
2026-09-25
CVE-2026-53493 Sin clasificar containerd containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high… Sin parche aún 2026-09-25
CVE-2026-17545 Sin clasificar PHP On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, CONIN$ and CONOUT$… Sin parche aún 2026-09-25
CVE-2026-2270 Sin clasificar Kubernetes — Debian:12: 1.20.5+really1.20.2-1
Debian:13: 1.20.5+really1.20.2-1
Debian:14: 1.20.5+really1.20.2-1
2026-09-24
CVE-2026-79994 Sin clasificar Docker The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the… Sin parche aún 2026-09-15
CVE-2026-42533 Sin clasificar Nginx A security issue was fixed in nginx. Ubuntu:22.04: 1.18.0-6ubuntu14.21
Ubuntu:24.04: 1.24.0-2ubuntu7.18
Ubuntu:26.04: 1.28.3-2ubuntu1.11
2026-09-14
CVE-2026-53495 Sin clasificar containerd containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely… Sin parche aún 2026-09-14
CVE-2026-17543 Sin clasificar PHP php8.1, php8.3, php8.5 vulnerabilities Ubuntu:22.04: 8.1.2-1ubuntu2.26
Ubuntu:24.04: 8.3.6-0ubuntu0.24.04.11
Ubuntu:26.04: 8.5.4-0ubuntu1.3
2026-09-10

Datos de OSV.dev, que agrega los avisos de Debian, Ubuntu, Alpine y Rocky Linux. La severidad es la puntuación base CVSS 3.1 calculada a partir del vector publicado. Esta tabla se genera automáticamente y no sustituye a los avisos oficiales de tu distribución.

Buscar por software o distribución

Por software

Por distribución

Cómo se elabora esta lista

Qué software se vigila

El servicio que administramos en la práctica, no todo el catálogo: Kernel Linux, systemd, OpenSSH y OpenSSL como base; Nginx y Apache como servidores web; PostgreSQL y MariaDB como bases de datos; Docker, containerd y Kubernetes en contenedores; y PHP, Postfix y BIND. Se consulta sobre Debian 12, Ubuntu 24.04 y Alpine 3.20.

Qué queda fuera

Todo lo que no llega a un servidor en producción: escritorio, navegadores, aplicaciones de usuario y hardware de consumo. Una lista que lo incluyera todo sería más larga y menos útil, porque obligaría a filtrar a mano lo que aquí ya viene filtrado.

Cómo leer las columnas

  • Severidad es la puntuación base CVSS 3.1 calculada desde el vector publicado, no una estimación nuestra. Cuando el mismo fallo tiene vectores distintos según la distribución, se muestra el más grave.
  • Corregido en lista las versiones que ya incluyen el parche, por distribución. Que aparezca una versión de Debian 13 y no de Debian 12 significa exactamente eso: el parche existe, pero todavía no ha llegado a esa rama.
  • Sin parche aún significa que ninguna distribución ha publicado versión corregida. Son las que conviene mirar primero, porque la respuesta no es actualizar sino mitigar.

La tabla se regenera automáticamente y ninguna parte de ella la redacta un modelo de lenguaje: son datos copiados de su fuente. Para decidir qué hacer con un aviso concreto, la referencia sigue siendo el aviso oficial de tu distribución, enlazado en cada fila.

Sigue los avisos

Recopilamos estos avisos a diario. Puedes seguirlos por RSS en tu lector habitual, o suscribirte solo a los de un software o una distribución concretos desde su página.

Suscribirse por RSS

¿Quién aplica estos parches en tus servidores?

Revisar avisos es la parte fácil. Lo que cuesta es decidir qué urge, probarlo y aplicarlo sin cortar el servicio. Si eso hoy no lo lleva nadie, hablamos.