Known Vulnerabilities for Http Server by Oracle
Listed below are 10 of the newest known vulnerabilities associated with "Http Server" by "Oracle".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-71476 json | Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hos... | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-71310 json | rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0... | Not Provided | 2026-08-05 | 2026-08-06 |
| CVE-2026-71280 json | go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Client w... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-71271 json | Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate IP against a reservedCIDRs l... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-71270 json | Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanitizer/... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-71235 json | Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side whe... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-71211 json | MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-70616 json | boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticated user to permanently exh... | Not Provided | 2026-08-05 | 2026-08-06 |
| CVE-2026-70605 json | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9... | Not Provided | 2026-08-05 | 2026-08-06 |
| CVE-2026-70595 json | Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such a... | Not Provided | 2026-08-05 | 2026-08-06 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Http Server | 9.2.0.8 | |||
| Application | Oracle | Http Server | 9.2.0.7 | |||
| Application | Oracle | Http Server | 9.2.0 | |||
| Application | Oracle | Http Server | 9.1 | |||
| Application | Oracle | Http Server | 9.0.4.1.0 | |||
| Application | Oracle | Http Server | 9.0.4.0.0 | |||
| Application | Oracle | Http Server | 9.0.3.1 | |||
| Application | Oracle | Http Server | 9.0.2.3 | |||
| Application | Oracle | Http Server | 9.0.2 | |||
| Application | Oracle | Http Server | 9.0.1.5 | |||
| Application | Oracle | Http Server | 9.0.1 | |||
| Application | Oracle | Http Server | 8.1.7 | |||
| Application | Oracle | Http Server | 2.1 | |||
| Application | Oracle | Http Server | 12.2.1.4.0 | |||
| Application | Oracle | Http Server | 12.2.1.3.0 | |||
| Application | Oracle | Http Server | 12.2.1.2.0 | |||
| Application | Oracle | Http Server | 12.2.1.1.0 | |||
| Application | Oracle | Http Server | 12.2.1.1 | |||
| Application | Oracle | Http Server | 12.2.1 | |||
| Application | Oracle | Http Server | 12.1.3.0.0 |