Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.

Apache HTTP Server Cross-Site Scripting in URL Handling

BELL-CVE-2026-23265
Summary

A vulnerability in Apache's URL handling could allow an attacker to inject malicious code into websites. This could potentially allow an attacker to steal user data or take control of a website. Apache has released a patch to fix this issue, so it's essential to update your Apache server immediately.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
bellsoft linux-lts > 6.1.164-r0
bellsoft linux-lts > 6.12.74-r0
bellsoft linux-lts > 6.12.76-r0
Original title
BELL-CVE-2026-23265
Published: 21 Mar 2026 · Updated: 21 Mar 2026 · First seen: 21 Mar 2026