An advisory published on October 1, 2026 rates a mod_ssl flaw in Apache HTTP Server as low severity. It concerns file-related expressions in SSLRequire.
The CVE-2026-59797 advisory reports an improper privilege management flaw in Apache HTTP Server's mod_ssl. The issue concerns SSLRequire and file-related expressions, including the use of ap_expr in .htaccess files. The reported severity is low, and affected versions range from 2.4.0 through 2.4.68. The notice credits researchers with the discovery; their names are omitted here.
Published on October 1, 2026, the item is identified as an automatic translation of a message from the oss-sec feed. To confirm the scope, original wording, and any remediation guidance, consult the original notice in the feed archive and check Apache HTTP Server's official advisories. Do not infer a fixed version or mitigation that those sources do not state.