Packages
Get Gentoo!
gentoo.org sites
gentoo.org
Wiki
Bugs
Forums
Packages
Planet
Archives
Sources
Infra Status
Home
Packages
Maintainers
USE flags
Architectures
About
www-servers
The www-servers category contains web server packages.
Packages
Outdated
3
Pull requests
3
Bugs
104
Security
18
Security Bug Reports
<www-servers/caddy-2.5.2: oob read allows for DoS
860147 - Assigned to Gentoo Security
<www-servers/h2o-2.2.6-r2: HTTP/2 Rapid Reset vulnerabilitiy
915567 - Assigned to Gentoo Security
<www-servers/tomcat-{8.5.94,9.0.81,10.1.14}: Multiple vulnerabilities
915568 - Assigned to Gentoo Security
<www-servers/caddy-2.7.5: http/2 rapid reset vulnerability
918413 - Assigned to Gentoo Security
<www-servers/tomcat-{10.1.16,9.0.83,8.5.96}: http request smuggling
918700 - Assigned to Gentoo Security
<www-servers/h2o-2.3.0_pre20241014: multiple vulnerabilities
919882 - Assigned to Gentoo Security
<www-servers/puma-6.4.3: Header normalization allows for client to clobber proxy set headers
939950 - Assigned to Gentoo Security
<www-servers/apache-2.4.65: 'RewriteCond expr' always evaluates to true
960609 - Assigned to Gentoo Security
<www-servers/tomcat-{9.0.107:9,10.1.43:10,11.0.9:11}: multiple vulnerabilities across all versions
960748 - Assigned to Gentoo Security
<www-servers/lighttpd-1.4.80: HTTP/2 MadeYouReset vulnerability
961511 - Assigned to Gentoo Security
<www-servers/lighttpd-1.4.81: may not reject disallowed headers
961817 - Assigned to Gentoo Security
=www-servers/tomcat-{11.0.9,10.1.43,9.0.107} DoS in HTTP/2 due to client triggered stream reset
962176 - Assigned to Gentoo Security
<www-servers/tomcat-{9.0.111,10.1.48,11.0.13}: multiple vulnerabilities
965262 - Assigned to Gentoo Security
<www-servers/tomcat-{9.0.118,10.1.55,11.0.22}: Multiple vulnerabilities
972560 - Assigned to Gentoo Security
<www-servers/lighttpd-1.4.83: Multiple vulnerabilities (HTTP/2?)
977561 - Assigned to Gentoo Security
www-servers/tomcat: multiple vulnerabilities
981491 - Assigned to Gentoo Security
<www-servers/nginx-{1.30.5,1.31.6}: Buffer overflow with ngx_http_v3_module
982593 - Assigned to Gentoo Security
<www-servers/vinyl-cache-{9.0.2,9.1.0}: VCL string methods workspace overflow
982653 - Assigned to Gentoo Security
Contact Information
Please file new vulnerability reports on
Gentoo Bugzilla
and assign them to the Gentoo Security product and Vulnerabilities component.