A bulletin published on October 1, 2026 reports a low-severity vulnerability in Apache HTTP Server versions 2.4.30 through 2.4.68.
A bulletin attributed to Eric Covener and published on October 1, 2026 in the oss-sec feed describes CVE-2026-63718 in Apache HTTP Server. It gives the issue a low severity rating and lists versions 2.4.30 through 2.4.68 as affected.
According to the report, mod_proxy_uwsgi may inconsistently interpret a uwsgi response created with Transfer-Encoding, leading to HTTP request or response smuggling. Qing Xu is credited with discovering the issue. The supplied text does not state a fix or describe mitigation steps; consult the original notice in the oss-sec feed and verify details against official Apache sources before taking action.