Skip to content
Denial of Service Vulnerability in HTTP-Date Affects Ubuntu Systems

Denial of Service Vulnerability in HTTP-Date Affects Ubuntu Systems

First seen 24 Jul 2026, 03:31 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 25, 2026 at 01:49 UTC
  • A denial of service vulnerability exists in the HTTP-Date module affecting Ubuntu systems.
  • Attackers can exploit this flaw by sending specially crafted date strings.
  • Users must update to specific package versions to mitigate the risk.

A vulnerability in the HTTP-Date module has been identified, allowing attackers to exploit improper parsing of date strings. This could lead to excessive resource consumption and denial of service on affected systems. The flaw impacts multiple Ubuntu versions, including 26.04 LTS, 24.04 LTS, and 22.04 LTS. Users are advised to update their systems to the latest package versions to mitigate the risk. The specific package versions that address the issue are libhttp-date-perl 6.06-1ubuntu0.26.04.1 for Ubuntu 26.04 LTS, and earlier versions for the other supported releases. The vulnerability does not have a CVE assigned yet, but it is critical for users to apply the updates promptly to avoid potential service disruptions.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 59d ago How this analysis works

Timeline

2026-07-23
Vulnerability discovered in HTTP-Date module
HTTP-Date was found to improperly parse date strings, leading to potential denial of service.
Linuxsecurity
2026-07-23
Ubuntu Security Notice USN-8599-1 issued
Ubuntu released an advisory detailing the vulnerability and recommended updates for affected systems.
Ubuntu

More articles in this cluster (2)

Following this threat?

Track Ubuntu in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed