Fedora Account System
Red Hat Associate
Red Hat Customer
SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker. Requires an unlikely configuration where mod_headers is configured to modify the Content-Type request or response header with a value provided in the HTTP request.
This issue has been addressed in the following products: Red Hat JBoss Core Services 2.4.62.SP5 Via RHSA-2026:56869 https://access.redhat.com/errata/RHSA-2026:56869
This issue has been addressed in the following products: JBoss Core Services for RHEL 8 Via RHSA-2026:56868 https://access.redhat.com/errata/RHSA-2026:56868