RHSA-2026:41906HighCVSS 7.7

Red Hat Security Advisory: httpd security, bug fix, and enhancement update

Published
July 20, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (13)

📋 Description

CVE-2024-42516 — httpd: incomplete fix for CVE-2023-38709 CVE-2026-24072 — Apache HTTP Server: mod_rewrite: Apache HTTP Server: Privilege Escalation via .htaccess file manipulation CVE-2026-29169 — httpd: NULL pointer dereference via specially crafted request CVE-2026-33006 — httpd: mod_auth_digest: timing attack allows a bypass of digest authentication CVE-2026-34355 — httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass CVE-2026-34356 — httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers CVE-2026-42535 — httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue CVE-2026-42536 — httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc CVE-2026-43951 — httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime CVE-2026-44119 — httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges CVE-2026-44185 — httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server CVE-2026-44186 — httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server CVE-2026-44631 — httpd: Apache HTTP Server: Denial of Service via crafted regular expressions

🔗 References (16)