EulerOS Virtualization 2.10.1 : httpd (EulerOS-SA-2026-2822)

high Nessus Plugin ID 328603

Synopsis

The remote EulerOS Virtualization host is missing multiple security updates.

Description

According to the versions of the httpd packages installed, the EulerOS Virtualization installation on the remote host is affected by the following vulnerabilities :

Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data.(CVE-2026-29168)

An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.(CVE-2026-24072)

A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs.(CVE-2026-29169)

Buffer Over-read vulnerability in Apache HTTP Server.(CVE-2026-34059)

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.(CVE-2026-28780)

Tenable has extracted the preceding description block directly from the EulerOS Virtualization httpd security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected httpd packages.

See Also

http://www.nessus.org/u?d947ad86

Plugin Details

Severity: High

ID: 328603

File Name: EulerOS_SA-2026-2822.nasl

Version: 1.1

Type: Local

Published: 7/21/2026

Updated: 7/21/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.7

Percentile: 99.06

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-28780

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2026-24072

Vulnerability Information

CPE: cpe:/o:huawei:euleros:uvp:2.10.1, p-cpe:/a:huawei:euleros:httpd-filesystem, p-cpe:/a:huawei:euleros:httpd-tools, p-cpe:/a:huawei:euleros:httpd, p-cpe:/a:huawei:euleros:mod_ssl

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/EulerOS/release, Host/EulerOS/rpm-list, Host/EulerOS/uvp_version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/20/2026

Vulnerability Publication Date: 5/4/2026

Reference Information

CVE: CVE-2026-24072, CVE-2026-28780, CVE-2026-29168, CVE-2026-29169, CVE-2026-34059