Apache httpd security update (MINDBREEZE43566)
ID: MINDBREEZE43566
Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS
Severity: 7.5 High
Status: Final
First published: September 9, 2026
CVEs: CVE-2024-42516, CVE-2026-29169, CVE-2026-44631, CVE-2026-44186, CVE-2026-44185, CVE-2026-43951, CVE-2026-42536, CVE-2026-34356, CVE-2026-34355
Summary
- httpd: Heap Underflow in `ap_regname` via Signed Char Overflow
- httpd: Loop in `proxy_ftp_handler` in mod_proxy_ftp
- httpd: mod_dav_lock indirect lock crash
- httpd: mod_proxy_html buffer overflow
- httpd: mod_xml2enc heap overflow
- httpd: OOB Read in `merge_response_headers` can cause crash
- httpd: ProxyPassReverseCookieMap buffer overflow
- httpd: Stack Buffer Over-Read in mod_ssl OCSP `send_request`
- httpd: incomplete fix for CVE-2023-38709
Hotfix Information
Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS:
- Mindbreeze InSpire 26.5 Release
- Mindbreeze InSpire SaaS 26.5 Release