| Type: | SECURITY |
| Impact: | IMPORTANT |
| Release Date: | 2026-06-17 |
httpd
[2.4.37-65.0.1.8]
- Replace index.html with Oracle's index page oracle_index.html
[2.4.37-65.8]
- Resolves: RHEL-173558 - httpd:2.4/httpd: Apache HTTP Server mod_proxy_ajp:
Arbitrary code execution via heap-based buffer overflow (CVE-2026-28780)
- Resolves: RHEL-175074 - httpd:2.4/httpd: NULL pointer dereference can
cause a child process crash (CVE-2026-33007)
- Resolves: RHEL-175088 - httpd:2.4/httpd: off-by-one out-of-bounds reads
in AJP getter functions (CVE-2026-33857)
- Resolves: RHEL-175620 - httpd:2.4/httpd: NULL pointer dereference via
specially crafted request (CVE-2026-29169)
- Resolves: RHEL-175055 - httpd: heap-based buffer over-read and memory
disclosure in ajp_parse_data() (CVE-2026-34059)
[2.4.37-65.7]
- Resolves: RHEL-135054 - httpd: Apache HTTP Server: mod_userdir+suexec bypass
via AllowOverride FileInfo (CVE-2025-66200)
- Resolves: RHEL-135039 - httpd: Apache HTTP Server: CGI environment variable
override (CVE-2025-65082)
- Resolves: RHEL-134471 - httpd: Apache HTTP Server: Server Side Includes adds
query string to #exec cmd=... (CVE-2025-58098)
[2.4.37-65.6]
- Resolves: RHEL-127073 - mod_ssl: allow more fine grained SSL SNI vhost check
to avoid unnecessary 421 errors after CVE-2025-23048 fix
- mod_ssl: add conf.d/snipolicy.conf to set 'SSLVHostSNIPolicy authonly' default
[2.4.37-65.5]
- Resolves: RHEL-99944 - CVE-2025-49812 httpd: HTTP Session Hijack via a TLS upgrade
- Resolves: RHEL-99969 - CVE-2024-47252 httpd: insufficient escaping of
user-supplied data in mod_ssl
- Resolves: RHEL-99961 - CVE-2025-23048 httpd: access control bypass by trusted
clients is possible using TLS 1.3 session resumption
[2.4.37-65.4]
- Resolves: RHEL-87641 - apache Bug 63192 - mod_ratelimit breaks HEAD requests
[2.4.37-65.3]
- Resolves: RHEL-56068 - Apache HTTPD no longer parse PHP files with
unicode characters in the name
[2.4.37-65.2]
- Resolves: RHEL-46040 - httpd:2.4/httpd: Security issues via backend
applications whose response headers are malicious or exploitable (CVE-2024-38476)
- Resolves: RHEL-53022 - Regression introduced by CVE-2024-38474 fix
[2.4.37-65.1]
- Resolves: RHEL-45812 - httpd:2.4/httpd: Substitution encoding issue
in mod_rewrite (CVE-2024-38474)
- Resolves: RHEL-45785 - httpd:2.4/httpd: Encoding problem in
mod_proxy (CVE-2024-38473)
- Resolves: RHEL-45777 - httpd:2.4/httpd: Improper escaping of output
in mod_rewrite (CVE-2024-38475)
- Resolves: RHEL-45758 - httpd:2.4/httpd: null pointer dereference
in mod_proxy (CVE-2024-38477)
- Resolves: RHEL-45743 - httpd:2.4/httpd: Potential SSRF
in mod_rewrite (CVE-2024-39573)
[2.4.37-65]
- Resolves: RHEL-31857 - httpd:2.4/httpd: HTTP response
splitting (CVE-2023-38709)
mod_http2
[1.15.7-10.6]
- Resolves: RHEL-182418 - mod_http2: HTTP/2: Remote Denial of Service via
compression bomb and Slowloris-style attack (CVE-2026-49975)
[1.15.7-10.5]
- Resolves: RHEL-166277 - httpd:2.4/httpd: Apache HTTP Server: HTTP/2 DoS by
Memory Increase (CVE-2025-53020)
[1.15.7-10.4]
- Resolves: RHEL-105186 - httpd:2.4/httpd: untrusted input from a client causes
an assertion to fail in the Apache mod_proxy_http2 module (CVE-2025-49630)
[1.15.7-10.3]
- Resolves: RHEL-58454 - mod_proxy_http2 failures after CVE-2024-38477 fix
- Resolves: RHEL-59017 - random failures in other requests on http/2 stream
when client resets one request
[1.15.7-10.2]
- Resolves: RHEL-71575: Wrong Content-Type when proxying using H2 protocol
[1.15.7-10.1]
- Resolves: RHEL-46214 - Access logs and ErrorDocument don't work when HTTP431
occurs using http/2 on RHEL8
[1.15.7-10]
- Resolves: RHEL-29817 - httpd:2.4/mod_http2: httpd: CONTINUATION frames
DoS (CVE-2024-27316)
[1.15.7-9.3]
- Resolves: RHEL-13367 - httpd:2.4/mod_http2: reset requests exhaust memory
(incomplete fix of CVE-2023-44487)(CVE-2023-45802)
[1.15.7-8.3]
- Resolves: #2177748 - CVE-2023-25690 httpd:2.4/httpd: HTTP request splitting
with mod_rewrite and mod_proxy
[1.15.7-7]
- Resolves: #2095650 - Dependency from mod_http2 on httpd broken
mod_md
[1:2.0.8-8.2]
- Resolves: RHEL-134487 - httpd:2.4/httpd: Apache HTTP Server: mod_md (ACME),
unintended retry intervals (CVE-2025-55753)
[1:2.0.8-8]
- Resolves: #1832844 - mod_md does not work with ACME server that does not
provide keyChange or revokeCert resources
[1:2.0.8-7]
- Resolves: #1747912 - add a2md(1) documentation
[1:2.0.8-6]
- Resolves: #1781263 - mod_md ACMEv1 crash
[1:2.0.8-5]
- Resolves: #1747898 - add mod_md package
[1:2.0.8-4]
- require mod_ssl, update package description
[1:2.0.8-3]
- rebuild against 2.4.41
[1:2.0.8-2]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
[1:2.0.8-1]
- update to 2.0.8
[2.0.3-1]
- Initial import (#1719248).
| CVE-2026-49975 |
| Release/Architecture | Filename | sha256 | Superseded By Advisory | Channel Label |
| Oracle Linux 8 (aarch64) | httpd-2.4.37-65.0.1.module+el8.10.0+90909+2fc0e3ca.8.src.rpm | ca8f97112bae23ebc445a7440247ed117ab54afa02cae95065b394e0ff46a535 | - | ol8_aarch64_appstream |
| mod_http2-1.15.7-10.module+el8.10.0+90909+2fc0e3ca.6.src.rpm | 901e89b3bfa79164ef63ae7f79760bff5282e904379dabb4745c60052db98abd | - | ol8_aarch64_appstream | |
| mod_md-2.0.8-8.module+el8.10.0+90899+db89cbcc.2.src.rpm | 9db8343d602b63ce893a5e6337b5adb88a72fb79432779565626f46e0767998b | - | ol8_aarch64_appstream | |
| httpd-2.4.37-65.0.1.module+el8.10.0+90909+2fc0e3ca.8.aarch64.rpm | ad315616ad2540b35c88546307fadf4d7272e5b48f6aa46088ccb50c8b313aaa | - | ol8_aarch64_appstream | |
| httpd-devel-2.4.37-65.0.1.module+el8.10.0+90909+2fc0e3ca.8.aarch64.rpm | 4088daeba64824ffa8b58eb5b43e7f89ce65e3d10e6bc2d282f82af7c05432af | - | ol8_aarch64_appstream | |
| httpd-filesystem-2.4.37-65.0.1.module+el8.10.0+90909+2fc0e3ca.8.noarch.rpm | b87bd01421bb56317318892b25dab8062cb2bd989c01d95d3f49593c2a188145 | - | ol8_aarch64_appstream | |
| httpd-manual-2.4.37-65.0.1.module+el8.10.0+90909+2fc0e3ca.8.noarch.rpm | 2e2a4deacee2cd3738181c15273ecaed2bf1345b55af34f2ffa376699a0cbb0c | - | ol8_aarch64_appstream | |
| httpd-tools-2.4.37-65.0.1.module+el8.10.0+90909+2fc0e3ca.8.aarch64.rpm | a620f2f61510c1d3f0992b5a67916785f8c550e596b27b47157a48e32f6881b8 | - | ol8_aarch64_appstream | |
| mod_http2-1.15.7-10.module+el8.10.0+90909+2fc0e3ca.6.aarch64.rpm | d8e2a4c7f91f2d4029383b407fb2523e3237a293db026298ece8b670f82bd516 | - | ol8_aarch64_appstream | |
| mod_ldap-2.4.37-65.0.1.module+el8.10.0+90909+2fc0e3ca.8.aarch64.rpm | 4343824e8c935b0f5cf1e29d6dff72432520296ea057e7cc31a5c7d578253853 | - | ol8_aarch64_appstream | |
| mod_md-2.0.8-8.module+el8.10.0+90899+db89cbcc.2.aarch64.rpm | 0076c2b3d4031d8b44a8267f229206b5b1a1aa912d18fd0506a11e1441a7fd56 | - | ol8_aarch64_appstream | |
| mod_proxy_html-2.4.37-65.0.1.module+el8.10.0+90909+2fc0e3ca.8.aarch64.rpm | 1ed20d67ac47a7157aaa1abb0105b4670711615c54527d86ab4583c30de7adb9 | - | ol8_aarch64_appstream | |
| mod_session-2.4.37-65.0.1.module+el8.10.0+90909+2fc0e3ca.8.aarch64.rpm | 7825d94c7363d130416f61677e493df16365585d5bb317702cd4b91c476338a8 | - | ol8_aarch64_appstream | |
| mod_ssl-2.4.37-65.0.1.module+el8.10.0+90909+2fc0e3ca.8.aarch64.rpm | a1baa348556f9c6a43bdea056bdb9a79307f359cc2cd40d1e8b72a14bb45a394 | - | ol8_aarch64_appstream | |
| Oracle Linux 8 (x86_64) | httpd-2.4.37-65.0.1.module+el8.10.0+90909+2fc0e3ca.8.src.rpm | ca8f97112bae23ebc445a7440247ed117ab54afa02cae95065b394e0ff46a535 | - | ol8_x86_64_appstream |
| mod_http2-1.15.7-10.module+el8.10.0+90909+2fc0e3ca.6.src.rpm | 901e89b3bfa79164ef63ae7f79760bff5282e904379dabb4745c60052db98abd | - | ol8_x86_64_appstream | |
| mod_md-2.0.8-8.module+el8.10.0+90899+db89cbcc.2.src.rpm | 9db8343d602b63ce893a5e6337b5adb88a72fb79432779565626f46e0767998b | - | ol8_x86_64_appstream | |
| httpd-2.4.37-65.0.1.module+el8.10.0+90909+2fc0e3ca.8.x86_64.rpm | 00b059d57af24bceac787b510752c768fc397e662cf6f35a8e93af68d0282a25 | - | ol8_x86_64_appstream | |
| httpd-devel-2.4.37-65.0.1.module+el8.10.0+90909+2fc0e3ca.8.x86_64.rpm | a03baf28227e2ac939788d7ff158bebb61d80db33d2b8c6f1b2694ad7529bdd3 | - | ol8_x86_64_appstream | |
| httpd-filesystem-2.4.37-65.0.1.module+el8.10.0+90909+2fc0e3ca.8.noarch.rpm | b87bd01421bb56317318892b25dab8062cb2bd989c01d95d3f49593c2a188145 | - | ol8_x86_64_appstream | |
| httpd-manual-2.4.37-65.0.1.module+el8.10.0+90909+2fc0e3ca.8.noarch.rpm | 2e2a4deacee2cd3738181c15273ecaed2bf1345b55af34f2ffa376699a0cbb0c | - | ol8_x86_64_appstream | |
| httpd-tools-2.4.37-65.0.1.module+el8.10.0+90909+2fc0e3ca.8.x86_64.rpm | 83ffa75b83d9d0453498bced5c3dbb3b85f716d02726aa739ce921bcb86c3953 | - | ol8_x86_64_appstream | |
| mod_http2-1.15.7-10.module+el8.10.0+90909+2fc0e3ca.6.x86_64.rpm | a5469ab90adf64c49e651843b496d80aff536e3464ba75376591c65b46252e26 | - | ol8_x86_64_appstream | |
| mod_ldap-2.4.37-65.0.1.module+el8.10.0+90909+2fc0e3ca.8.x86_64.rpm | 923ea45e45fe7306098aa1d38f07e9dfee49d24b615e95205c6c2ad6e0615cf4 | - | ol8_x86_64_appstream | |
| mod_md-2.0.8-8.module+el8.10.0+90899+db89cbcc.2.x86_64.rpm | d840fcfb5901dd6d2d0589f27ddaa733291ebfdd46645f898df94326b1e53f0a | - | ol8_x86_64_appstream | |
| mod_proxy_html-2.4.37-65.0.1.module+el8.10.0+90909+2fc0e3ca.8.x86_64.rpm | b1a43fadeb490930124c7e485f34b7fa45b5b062535ee836d6931af6f447ae9b | - | ol8_x86_64_appstream | |
| mod_session-2.4.37-65.0.1.module+el8.10.0+90909+2fc0e3ca.8.x86_64.rpm | 0381846cc1fc842960cb1bc72b7a940d4767cd3a0acc31ffa035c516664fd8f2 | - | ol8_x86_64_appstream | |
| mod_ssl-2.4.37-65.0.1.module+el8.10.0+90909+2fc0e3ca.8.x86_64.rpm | b49baa3ea5ac35222d98d3e0749d5b1ed17261c50c3dd00b3cf93cc06e648210 | - | ol8_x86_64_appstream | |
This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team