RHSA-2026:27201HighCVSS 8.2

Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.62 SP4 security update

Published
June 22, 2026
Last Modified
August 21, 2026

🔗 CVE IDs covered (13)

📋 Description

CVE-2025-53020 — mod_http2: Apache HTTP Server: HTTP/2 DoS by Memory Increase CVE-2026-2673 — openssl: OpenSSL TLS 1.3 server may choose unexpected key agreement group CVE-2026-27135 — nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination CVE-2026-28780 — Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow CVE-2026-29168 — httpd: mod_md: unrestricted OCSP response leads to resource exhaustion CVE-2026-29169 — httpd: NULL pointer dereference via specially crafted request CVE-2026-31790 — openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key CVE-2026-33007 — httpd: mod_authn_socache: NULL pointer dereference can cause a child process crash CVE-2026-33857 — httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions CVE-2026-34032 — httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check CVE-2026-34059 — httpd: mod_proxy_ajp: heap-based buffer over-read and memory disclosure in ajp_parse_data() CVE-2026-45186 — libexpat: denial of service via crafted XML input CVE-2026-49975 — httpd: httpd: HTTP/2 Remote Denial of Service via compression bomb and Slowloris-style attack

🎯 Affected products1

  • Red Hat JBoss Core Services 2.4.62.SP4

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The attack surface can be reduced by disabling HTTP/2 support in Apache. Follow the guidance in Red Hat KCS article to: - Remove h2 and h2c from the Protocols directive - Disable mod_http2 and mod_proxy_http2 modules (if not required) https://access.redhat.com/node/7056356 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Disabling mod_md and restarting httpd will mitigate this flaw. Workaround: Disabling mod_dav_lock and restarting httpd will mitigate this flaw. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Disabling mod_authn_socache and restarting httpd will mitigate this flaw. Workaround: Disabling mod_proxy_ajp and restarting httpd will mitigate this flaw. Workaround: To mitigate this vulnerability, restrict the maximum size of incoming XML payloads. It is especially critical to limit the decompressed size if the application accepts compressed XML files. Also, consider running the application inside a container or a restricted environment to ensure that the high consumption of CPU resources does not affect the host system. Workaround: See the security bulletin for a detailed mitigation procedure.

🔗 References (17)