Denial of Service Vulnerability in HTTP-Date Affects Ubuntu Systems

Denial of Service Vulnerability in HTTP-Date Affects Ubuntu Systems

First seen 24 Jul 2026, 03:31 UTC UbuntuLinuxsecurity 83% similarity 57.8

Article Content

Browse articles
ThreatCluster

A vulnerability in the HTTP-Date module has been identified, allowing attackers to exploit improper parsing of date strings. This could lead to excessive resource consumption and denial of service on affected systems. The flaw impacts multiple Ubuntu versions, including 26.04 LTS, 24.04 LTS, and 22.04 LTS. Users are advised to update their systems to the latest package versions to mitigate the risk. The specific package versions that address the issue are libhttp-date-perl 6.06-1ubuntu0.26.04.1 for Ubuntu 26.04 LTS, and earlier versions for the other supported releases. The vulnerability does not have a CVE assigned yet, but it is critical for users to apply the updates promptly to avoid potential service disruptions.

Key Points: • A denial of service vulnerability exists in the HTTP-Date module affecting Ubuntu systems. • Attackers can exploit this flaw by sending specially crafted date strings. • Users must update to specific package versions to mitigate the risk.

ThreatCluster AI

Timeline

2026-07-23
Vulnerability discovered in HTTP-Date module
HTTP-Date was found to improperly parse date strings, leading to potential denial of service.
Linuxsecurity
2026-07-23
Ubuntu Security Notice USN-8599-1 issued
Ubuntu released an advisory detailing the vulnerability and recommended updates for affected systems.
Ubuntu

Community

Browse all →