Ubuntu Security Notices USN-8419-1 USN-8419-1: HTTP-Daemon vulnerability Publication date 10 June 2026 Overview HTTP-Daemon could be made to run programs if it received specially crafted network traffic. Releases 26.04 LTS 25.10 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS 14.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Packages libhttp-daemon-perl - simple http server class Details It was discovered that HTTP-Daemon incorrectly handled untrusted input under certain circumstances. A remote attacker could possibly use this issue to execute arbitrary commands, create or overwrite arbitrary files, or expose sensitive information. It was discovered that HTTP-Daemon incorrectly handled untrusted input under certain circumstances. A remote attacker could possibly use this issue to execute arbitrary commands, create or overwrite arbitrary files, or expose sensitive information. Update instructions In general, a standard system update will make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 26.04 LTS resolute libhttp-daemon-perl – 6.16-1ubuntu0.26.04.1 25.10 questing libhttp-daemon-perl – 6.16-1ubuntu0.25.10.1 24.04 LTS noble libhttp-daemon-perl – 6.16-1ubuntu0.24.04.1 22.04 LTS jammy libhttp-daemon-perl – 6.13-1ubuntu0.2 20.04 LTS focal libhttp-daemon-perl – 6.06-1ubuntu0.1+esm1 Ubuntu Pro Fix available with Ubuntu Pro . 18.04 LTS bionic libhttp-daemon-perl – 6.01-1ubuntu0.1+esm1 Ubuntu Pro Fix available with Ubuntu Pro . 16.04 LTS xenial libhttp-daemon-perl – 6.01-1ubuntu0.16.04~esm2 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. 14.04 LTS trusty libhttp-daemon-perl – 6.01-1ubuntu0.14.04~esm2 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-8450 CVE-2026-8450
A critical vulnerability (CVE-2026-8450, CVSS 9.1) in the libhttp-daemon-perl package allows a remote attacker to execute arbitrary commands, create or overwrite files, or expose sensitive information by sending specially crafted network traffic. The vulnerability affects multiple Ubuntu LTS releases, including 26.04 LTS, 25.10, 24.04 LTS, 22.04 LTS, 20.04 LTS, 18.04 LTS, 16.04 LTS, and 14.04 LTS. A standard system update to the specific patched package versions listed in the USN is required to remediate the issue.