Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:47046: Important: httpd security update

  • What: Security update for httpd
  • Impact: Addresses multiple vulnerabilities in the Apache HTTP Server
Read Full Article →

Red Hat Product Errata RHSA-2026:47046 - Security Advisory Issued: 2026-07-28 Updated: 2026-07-28 RHSA-2026:47046 - Security Advisory Overview Updated Packages Synopsis Important: httpd security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for httpd is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server. Security Fix(es): httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516) httpd: mod_proxy_ajp: heap-based buffer over-read and memory disclosure in ajp_parse_data() (CVE-2026-34059) httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check (CVE-2026-34032) httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions (CVE-2026-33857) httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169) httpd: mod_authn_socache: NULL pointer dereference can cause a child process crash (CVE-2026-33007) Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow (CVE-2026-28780) httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356) httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185) httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631) httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536) httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64 Fixes BZ - 2374549 - CVE-2024-42516 httpd: incomplete fix for CVE-2023-38709 BZ - 2464940 - CVE-2026-34059 httpd: mod_proxy_ajp: heap-based buffer over-read and memory disclosure in ajp_parse_data() BZ - 2464952 - CVE-2026-34032 httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check BZ - 2464953 - CVE-2026-33857 httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions BZ - 2465296 - CVE-2026-29169 httpd: NULL pointer dereference via specially crafted request BZ - 2465299 - CVE-2026-33007 httpd: mod_authn_socache: NULL pointer dereference can cause a child process crash BZ - 2466913 - CVE-2026-28780 Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow BZ - 2486395 - CVE-2026-34356 httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers BZ - 2486397 - CVE-2026-44185 httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server BZ - 2486399 - CVE-2026-44631 httpd: Apache HTTP Server: Denial of Service via crafted regular expressions BZ - 2486411 - CVE-2026-42536 httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc BZ - 2486414 - CVE-2026-34355 httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass CVEs CVE-2024-42516 CVE-2026-28780 CVE-2026-29169 CVE-2026-33007 CVE-2026-33857 CVE-2026-34032 CVE-2026-34059 CVE-2026-34355 CVE-2026-34356 CVE-2026-42536 CVE-2026-44185 CVE-2026-44631 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 SRPM httpd-2.4.63-1.el10_0.4.src.rpm SHA-256: bca6ebefffaad6a2e7834da7acf3c58cb46c464891d16e6057f46cc99301deff x86_64 httpd-2.4.63-1.el10_0.4.x86_64.rpm SHA-256: e0f68cfaf41108af49de710349a99d692ebc8255dae2bc888d919b3322f51de8 httpd-core-2.4.63-1.el10_0.4.x86_64.rpm SHA-256: 012d6253072cdac423f3e0d816211236738989b674d3f376084c40a2e450425f httpd-core-debuginfo-2.4.63-1.el10_0.4.x86_64.rpm SHA-256: c350b1dd1dcfe839b2ec282624631a0ebef0d1bb2ff5a082367c8113328d330d httpd-debuginfo-2.4.63-1.el10_0.4.x86_64.rpm SHA-256: bd1efa3892d08efd92d55198dfe02ee01b4506fd82ac42613ab987c5c63c5105 httpd-debugsource-2.4.63-1.el10_0.4.x86_64.rpm SHA-256: 7b6e0b71e5c62fb98969fbfa610c1c72d73f0af99585566b86e6e1640e2293fb httpd-devel-2.4.63-1.el10_0.4.x86_64.rpm SHA-256: 0d9ea36577950ca7f01b6e8846a6cd31a68ab36cc4386671e65c4cc1ed641efe httpd-filesystem-2.4.63-1.el10_0.4.noarch.rpm SHA-256: 7a4ffddbceccbe7997c142c12cf9b388923f23699128c35757f92f2f4f76b27d httpd-manual-2.4.63-1.el10_0.4.noarch.rpm SHA-256: 2861039a16936b0c403c699d11b9898856b33eaa402a1179300ae8be5cc9f103 httpd-tools-2.4.63-1.el10_0.4.x86_64.rpm SHA-256: 5645c5059c129c57cd0a65db4d727dddd474f891b0dd6599fcca454eaec0a582 httpd-tools-debuginfo-2.4.63-1.el10_0.4.x86_64.rpm SHA-256: 6c03d0d78a3fc1f4fa67a365f8b0c6ab83c4c43caddf5b2d88121d364336e62b mod_ldap-2.4.63-1.el10_0.4.x86_64.rpm SHA-256: 9249ecdbbd40d44630b352dc1457024317232a9326bf747a2e7240975309086a mod_ldap-debuginfo-2.4.63-1.el10_0.4.x86_64.rpm SHA-256: ada483250b604c58e7da517f676fc80b5a3539bc03faf7c770dd57a4b8ae7bb9 mod_lua-2.4.63-1.el10_0.4.x86_64.rpm SHA-256: fa1d238be46fd54a7625748289840b5ec383be65de250d8344716dd004d16cfa mod_lua-debuginfo-2.4.63-1.el10_0.4.x86_64.rpm SHA-256: e601de62442e61929d960b53f48261f45bd88c239567c930c9ae33a1a88339ae mod_proxy_html-2.4.63-1.el10_0.4.x86_64.rpm SHA-256: 68e77ff0a47c7602e27b52ea67de2ea99266d33d47b66dd8aadf9d69a076bff2 mod_proxy_html-debuginfo-2.4.63-1.el10_0.4.x86_64.rpm SHA-256: a10d69e8585558f4c88b33bfcbc8c945c461f4714a08bcbecc0ebc14bb5a2d81 mod_session-2.4.63-1.el10_0.4.x86_64.rpm SHA-256: 38f3315c61d84cbb7a11a1b85cece7c5e61d5465df23ce401e5a33d6a9cbf8cd mod_session-debuginfo-2.4.63-1.el10_0.4.x86_64.rpm SHA-256: 931859c4193610b40dd9b1c4c5d68187e219ec21bb51ef67f6ef0d9f444fd316 mod_ssl-2.4.63-1.el10_0.4.x86_64.rpm SHA-256: 07d7734a3c20bf50b6c7e4ae8df0aa25445b4219d84ff7a9f5a190c59fdbf2eb mod_ssl-debuginfo-2.4.63-1.el10_0.4.x86_64.rpm SHA-256: 2eb14613abc56928b80e3ed89573d422c886eb18a2a78c2572c66933daa97f77 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 SRPM httpd-2.4.63-1.el10_0.4.src.rpm SHA-256: bca6ebefffaad6a2e7834da7acf3c58cb46c464891d16e6057f46cc99301deff s390x httpd-2.4.63-1.el10_0.4.s390x.rpm SHA-256: 62a35f9b97b3fb01bc8f4485e909fe26d92b36efd91b0a3dfc4230c1dc00c119 httpd-core-2.4.63-1.el10_0.4.s390x.rpm SHA-256: 23b2b93e62741a723f833e64d9addf52e2b025d70d2550c8fd38b4bb9f4f60eb httpd-core-debuginfo-2.4.63-1.el10_0.4.s390x.rpm SHA-256: 6243dbfcf923e7889c7f1b659ab1e08a196499dd1f9478f7b7d4e5741ce900b1 httpd-debuginfo-2.4.63-1.el10_0.4.s390x.rpm SHA-256: 3936e70ea2222c64b1e327ccf73a8a7d4e2d478060350b7f7995600f9b894c0a httpd-debugsource-2.4.63-1.el10_0.4.s390x.rpm SHA-256: b70d85c1c7567676e24721b6897960efd1a7706a38d2291163ae71d488463c79 httpd-devel-2.4.63-1.el10_0.4.s390x.rpm SHA-256: 330f667a26e812c9f7900b39e61e3fb80e79349682dd4969108544d0abbeb73f httpd-filesystem-2.4.63-1.el10_0.4.noarch.rpm SHA-256: 7a4ffddbceccbe7997c142c12cf9b388923f23699128c35757f92f2f4f76b27d httpd-manual-2.4.63-1.el10_0.4.noarch.rpm SHA-256: 2861039a16936b0c403c699d11b9898856b33eaa402a1179300ae8be5cc9f103 httpd-tools-2.4.63-1.el10_0.4.s390x.rpm SHA-256: 8608781031400e978cf033abb49941394a9f3dc55f229d3a262ac74ceddc45a2 httpd-tools-debuginfo-2.4.63-1.el10_0.4.s390x.rpm SHA-256: d8fc2ed9c736771e4923d09a37f6427b1778960bda8b31a1e5ddf7ac87e4bf64 mod_ldap-2.4.63-1.el10_0.4.s390x.rpm SHA-256: 29cff7d192c6d2f65c1f01aab2e2cdaf914d84ff30552c5663edbe40ef65b24a mod_ldap-debuginfo-2.4.63-1.el10_0.4.s390x.rpm SHA-256: b640e8dc03a86d1fcafc7b6a1d3d613611438b3a74dd7a70432a3c9d77ca4d70 mod_lua-2.4.63-1.el10_0.4.s390x.rpm SHA-256: 483c962a1f1d5b1001a4b9228b5dd11e4047a08fc1edb25df34bd4de0d74313f mod_lua-debuginfo-2.4.63-1.el10_0.4.s390x.rpm SHA-256: 4d2229921f88e0c886068c0c00a306db9f1d47fa84eafe446b5d6ffba3a42488 mod_proxy_html-2.4.63-1.el10_0.4.s390x.rpm SHA-256: 49899d36ffa0f7b6c4f0dd8fade1ce1c880e13ecb29d3472a2518fe39dc88071 mod_proxy_html-debuginfo-2.4.63-1.el10_0.4.s390x.rpm SHA-256: 27084147b9f43ed5a99a9ad661d34f834b0c1db58a8da3021ad509add41b445e mod_session-2.4.63-1.el10_0.4.s390x.rpm SHA-256: a84d1027ff9c6cc814d928073c34eec676099574b49a8d96f746555e5b9c2218 mod_session-debuginfo-2.4.63-1.el10_0.4.s390x.rpm SHA-256: 8ed82156d49c19f30a0c925d73016f7bdbfd30c8de8253b9a1ccb6b7524349ca mod_ssl-2.4.63-1.el10_0.4.s390x.rpm SHA-256: 1b4a6ba95fd38d27bfa457f0e078c7b80cb8a5e2a9abe3de000e04d4441f4369 mod_ssl-debuginfo-2.4.63-1.el10_0.4.s390x.rpm SHA-256: 7fe528ef4d5064f7c147dbca052d68e77b669b423c2dc07ada3cdf8cfc50ad60 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 SRPM httpd-2.4.63-1.el10_0.4.src.rpm SHA-256: bca

Share this article