RHSA-2026:27200HighCVSS 8.2

Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.62 SP4 security update

Published
June 22, 2026
Last Modified
August 21, 2026

🔗 CVE IDs covered (10)

📋 Description

CVE-2025-53020 — mod_http2: Apache HTTP Server: HTTP/2 DoS by Memory Increase CVE-2026-27135 — nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination CVE-2026-28780 — Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow CVE-2026-29168 — httpd: mod_md: unrestricted OCSP response leads to resource exhaustion CVE-2026-29169 — httpd: NULL pointer dereference via specially crafted request CVE-2026-33007 — httpd: mod_authn_socache: NULL pointer dereference can cause a child process crash CVE-2026-33857 — httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions CVE-2026-34032 — httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check CVE-2026-34059 — httpd: mod_proxy_ajp: heap-based buffer over-read and memory disclosure in ajp_parse_data() CVE-2026-49975 — httpd: httpd: HTTP/2 Remote Denial of Service via compression bomb and Slowloris-style attack

🎯 Affected products67

  • Red Hat JBoss Core Services on RHEL 7 Server
  • Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-httpd-0:2.4.62-13.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-httpd-0:2.4.62-13.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-httpd-0:2.4.62-13.el8jbcs.src as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-httpd-0:2.4.62-13.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-httpd-debuginfo-0:2.4.62-13.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-httpd-debuginfo-0:2.4.62-13.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-httpd-devel-0:2.4.62-13.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-httpd-devel-0:2.4.62-13.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-httpd-manual-0:2.4.62-13.el7jbcs.noarch as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-httpd-manual-0:2.4.62-13.el8jbcs.noarch as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-httpd-selinux-0:2.4.62-13.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-httpd-selinux-0:2.4.62-13.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-httpd-tools-0:2.4.62-13.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-httpd-tools-0:2.4.62-13.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-httpd-tools-debuginfo-0:2.4.62-13.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-mod_http2-0:2.0.29-10.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-mod_http2-0:2.0.29-10.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-mod_http2-0:2.0.29-10.el8jbcs.src as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-mod_http2-0:2.0.29-10.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-mod_http2-debuginfo-0:2.0.29-10.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-mod_http2-debuginfo-0:2.0.29-10.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-mod_jk-0:1.2.50-14.redhat_1.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-mod_jk-0:1.2.50-14.redhat_1.el8jbcs.src as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-mod_jk-ap24-0:1.2.50-14.redhat_1.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-mod_jk-ap24-0:1.2.50-14.redhat_1.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-mod_jk-ap24-debuginfo-0:1.2.50-14.redhat_1.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-mod_jk-debuginfo-0:1.2.50-14.redhat_1.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-mod_ldap-0:2.4.62-13.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • +37 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The attack surface can be reduced by disabling HTTP/2 support in Apache. Follow the guidance in Red Hat KCS article to: - Remove h2 and h2c from the Protocols directive - Disable mod_http2 and mod_proxy_http2 modules (if not required) https://access.redhat.com/node/7056356 Workaround: Disabling mod_md and restarting httpd will mitigate this flaw. Workaround: Disabling mod_dav_lock and restarting httpd will mitigate this flaw. Workaround: Disabling mod_authn_socache and restarting httpd will mitigate this flaw. Workaround: Disabling mod_proxy_ajp and restarting httpd will mitigate this flaw. Workaround: See the security bulletin for a detailed mitigation procedure.

🔗 References (14)