Security and cryptography digest for 2026-10-02
Post-quantum cryptography discussions focused on contested claims against Classic McEliece and an updated NIST plan for FN-DSA, alongside a BSI advisory. Apache HTTP Server 2.4.69 also shipped fixes for several module vulnerabilities ranging from stack overflows to response smuggling.
Claimed quasipolynomial attack on Classic McEliece contested
A heated pqc-forum thread examined a claimed quasipolynomial distinguisher and decryption attack on Classic McEliece. Daniel Bernstein and other participants questioned both the feasibility of the attack and the ethics of how the claims were presented. The exchange matters because Classic McEliece is a long-standing code-based candidate in post-quantum standardization.
BSI advises against new Classic McEliece deployments
The German BSI issued a statement recommending against new use of Classic McEliece. A brief pqc-forum discussion weighed the implications for hybrid schemes and broader standardization efforts. Implementers and standards watchers should note the official guidance shift on this code-based algorithm.
NIST revises FN-DSA plan for FIPS 206
NIST published an updated plan for FN-DSA in FIPS 206 that requires fixed-point arithmetic and exact-match KAT signing for validation. Forum contributors reviewed the technical mandates. The changes directly affect implementers preparing Falcon-derived signatures for conformance testing.
Stack overflow in Apache mod_vhost_alias
Apache HTTP Server disclosed CVE-2026-63292, a moderate stack overflow in mod_vhost_alias. The flaw is fixed in version 2.4.69. Operators relying on virtual-host aliasing should upgrade to eliminate the overflow risk.
Use-after-free in Apache mod_http2
CVE-2026-57941 reports a moderate use-after-free and wild write in mod_http2 caused by shared session->bbtmp re-entrancy. The issue is resolved in Apache HTTP Server 2.4.69. Deployments with HTTP/2 enabled need the patch to avoid memory corruption.
Denial-of-service in Apache mod_auth_digest
Apache HTTP Server 2.4.69 fixes CVE-2026-73637, a low-severity use-after-free denial-of-service in mod_auth_digest when AuthDigestNcCheck is enabled. The condition permits a DoS under that configuration. Sites using digest authentication should apply the update.
Limited RCE via CGI redirects in Apache
CVE-2026-42356 describes a low-severity limited remote code execution path for certain internal redirects to non-CGI files inside CGI directories. The problem is corrected in 2.4.69. Administrators running CGI should upgrade after reviewing the scope of the redirect handling flaw.
Response smuggling in Apache mod_proxy_uwsgi
Apache HTTP Server 2.4.69 closes CVE-2026-63718, a low-severity Transfer-Encoding response smuggling issue in mod_proxy_uwsgi. The fix removes the smuggling vector. Proxy setups that forward to uwsgi backends benefit from the release.