RHSA-2026:47046HighCVSS 8.2

Red Hat Security Advisory: httpd security update

Published
July 28, 2026
Last Modified
August 7, 2026

🔗 CVE IDs covered (12)

📋 Description

CVE-2024-42516 — httpd: incomplete fix for CVE-2023-38709 CVE-2026-28780 — Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow CVE-2026-29169 — httpd: NULL pointer dereference via specially crafted request CVE-2026-33007 — httpd: mod_authn_socache: NULL pointer dereference can cause a child process crash CVE-2026-33857 — httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions CVE-2026-34032 — httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check CVE-2026-34059 — httpd: mod_proxy_ajp: heap-based buffer over-read and memory disclosure in ajp_parse_data() CVE-2026-34355 — httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass CVE-2026-34356 — httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers CVE-2026-42536 — httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc CVE-2026-44185 — httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server CVE-2026-44631 — httpd: Apache HTTP Server: Denial of Service via crafted regular expressions

🎯 Affected products76

  • Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-0:2.4.63-1.el10_0.4.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-0:2.4.63-1.el10_0.4.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-0:2.4.63-1.el10_0.4.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-0:2.4.63-1.el10_0.4.src as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-0:2.4.63-1.el10_0.4.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-core-0:2.4.63-1.el10_0.4.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-core-0:2.4.63-1.el10_0.4.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-core-0:2.4.63-1.el10_0.4.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-core-0:2.4.63-1.el10_0.4.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-core-debuginfo-0:2.4.63-1.el10_0.4.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-core-debuginfo-0:2.4.63-1.el10_0.4.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-core-debuginfo-0:2.4.63-1.el10_0.4.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-core-debuginfo-0:2.4.63-1.el10_0.4.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-debuginfo-0:2.4.63-1.el10_0.4.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-debuginfo-0:2.4.63-1.el10_0.4.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-debuginfo-0:2.4.63-1.el10_0.4.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-debuginfo-0:2.4.63-1.el10_0.4.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-debugsource-0:2.4.63-1.el10_0.4.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-debugsource-0:2.4.63-1.el10_0.4.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-debugsource-0:2.4.63-1.el10_0.4.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-debugsource-0:2.4.63-1.el10_0.4.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-devel-0:2.4.63-1.el10_0.4.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-devel-0:2.4.63-1.el10_0.4.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-devel-0:2.4.63-1.el10_0.4.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-devel-0:2.4.63-1.el10_0.4.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-filesystem-0:2.4.63-1.el10_0.4.noarch as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-manual-0:2.4.63-1.el10_0.4.noarch as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-tools-0:2.4.63-1.el10_0.4.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • httpd-tools-0:2.4.63-1.el10_0.4.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • +46 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Disabling mod_dav_lock and restarting httpd will mitigate this flaw. Workaround: Disabling mod_authn_socache and restarting httpd will mitigate this flaw. Workaround: Disabling mod_proxy_ajp and restarting httpd will mitigate this flaw. Workaround: Disable the `mod_proxy_html` module if it is not essential for your Apache HTTP Server configuration. If `mod_proxy_html` is required, restrict its use to trusted backend servers only, employing network segmentation and access controls. After modifying the configuration, reload the httpd service for changes to apply, which may cause a brief service interruption. Steps to disable: Open /etc/httpd/conf.modules.d/00-proxy.conf. Add a # to comment out the line: LoadModule proxy_html_module modules/mod_proxy_html.so Verify configuration syntax: apachectl configtest Apply the change gracefully: systemctl reload httpd Workaround: To prevent this denial-of-service flaw, ensure your Apache proxy rules only connect to highly trusted backend servers. If you must proxy traffic to unverified or external backends, disable the cookie-rewriting features. Steps to Mitigate: Open your Apache configuration file (e.g., /etc/httpd/conf/httpd.conf). Locate and comment out any ProxyPassReverseCookieDomain or ProxyPassReverseCookiePath lines pointing to untrusted backends by adding a # at the start of the line. Test your syntax: apachectl configtest Apply changes gracefully: systemctl reload httpd Note: This may cause a brief service interruption. Workaround: To mitigate this vulnerability, disable the `mod_xml2enc` module if its functionality for XML internationalization is not essential. This can be done by commenting out the `LoadModule xml2enc_module modules/mod_xml2enc.so` directive in the Apache HTTP Server configuration. A service restart is required for the change to take effect. ```bash # Edit the Apache configuration file, e.g., /etc/httpd/conf.modules.d/00-base.conf # Comment out the line: # LoadModule xml2enc_module modules/mod_xml2enc.so # Reload the httpd service sudo systemctl reload httpd ``` *Note: Disabling `mod_xml2enc` will cause any configurations relying heavily on `mod_proxy_html` or raw HTML/XML encoding conversions to function incorrectly or fail. Red Hat strongly recommends upgrading to a patched version of `httpd` as soon as it becomes available for your specific RHEL channel.* Workaround: To mitigate this issue, ensure that Apache HTTP Server is configured to only communicate with trusted OCSP responders. If OCSP validation or stapling is not a critical requirement for your deployment, consider disabling it. This can be achieved by adjusting mod_ssl directives in your Apache HTTP Server configuration. For example, add or modify the following lines: ~~~ SSLOCSPEnable off SSLUseStapling off ~~~ After modifying the configuration, reload the httpd service for the changes to take effect safely without interrupting active connections: ~~~ sudo systemctl reload httpd ~~~ Workaround: Only loadtrustedApache configuration; the bug triggers oncrafted regexin config at start/reload (DirectoryMatch,Directory ~,ProxyMatch, etc.). Keep AllowOverride None where possible so untrusted users cannot inject regex via .htaccess. Restrict who can change httpdconfig and reload the service.

🔗 References (15)