ELSA-2026-42828

ELSA-2026-42828 - httpd:2.4 security, bug fix, and enhancement update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-07-22

Description


httpd
[2.4.37-65.0.1.8]
- Replace index.html with Oracle's index page oracle_index.html

[2.4.37-65.8]
- Resolves: RHEL-173558 - httpd:2.4/httpd: Apache HTTP Server mod_proxy_ajp:
Arbitrary code execution via heap-based buffer overflow (CVE-2026-28780)
- Resolves: RHEL-175074 - httpd:2.4/httpd: NULL pointer dereference can
cause a child process crash (CVE-2026-33007)
- Resolves: RHEL-175088 - httpd:2.4/httpd: off-by-one out-of-bounds reads
in AJP getter functions (CVE-2026-33857)
- Resolves: RHEL-175620 - httpd:2.4/httpd: NULL pointer dereference via
specially crafted request (CVE-2026-29169)
- Resolves: RHEL-175055 - httpd: heap-based buffer over-read and memory
disclosure in ajp_parse_data() (CVE-2026-34059)

[2.4.37-65.7]
- Resolves: RHEL-135054 - httpd: Apache HTTP Server: mod_userdir+suexec bypass
via AllowOverride FileInfo (CVE-2025-66200)
- Resolves: RHEL-135039 - httpd: Apache HTTP Server: CGI environment variable
override (CVE-2025-65082)
- Resolves: RHEL-134471 - httpd: Apache HTTP Server: Server Side Includes adds
query string to #exec cmd=... (CVE-2025-58098)

[2.4.37-65.6]
- Resolves: RHEL-127073 - mod_ssl: allow more fine grained SSL SNI vhost check
to avoid unnecessary 421 errors after CVE-2025-23048 fix
- mod_ssl: add conf.d/snipolicy.conf to set 'SSLVHostSNIPolicy authonly' default

[2.4.37-65.5]
- Resolves: RHEL-99944 - CVE-2025-49812 httpd: HTTP Session Hijack via a TLS upgrade
- Resolves: RHEL-99969 - CVE-2024-47252 httpd: insufficient escaping of
user-supplied data in mod_ssl
- Resolves: RHEL-99961 - CVE-2025-23048 httpd: access control bypass by trusted
clients is possible using TLS 1.3 session resumption

[2.4.37-65.4]
- Resolves: RHEL-87641 - apache Bug 63192 - mod_ratelimit breaks HEAD requests

[2.4.37-65.3]
- Resolves: RHEL-56068 - Apache HTTPD no longer parse PHP files with
unicode characters in the name

[2.4.37-65.2]
- Resolves: RHEL-46040 - httpd:2.4/httpd: Security issues via backend
applications whose response headers are malicious or exploitable (CVE-2024-38476)
- Resolves: RHEL-53022 - Regression introduced by CVE-2024-38474 fix

[2.4.37-65.1]
- Resolves: RHEL-45812 - httpd:2.4/httpd: Substitution encoding issue
in mod_rewrite (CVE-2024-38474)
- Resolves: RHEL-45785 - httpd:2.4/httpd: Encoding problem in
mod_proxy (CVE-2024-38473)
- Resolves: RHEL-45777 - httpd:2.4/httpd: Improper escaping of output
in mod_rewrite (CVE-2024-38475)
- Resolves: RHEL-45758 - httpd:2.4/httpd: null pointer dereference
in mod_proxy (CVE-2024-38477)
- Resolves: RHEL-45743 - httpd:2.4/httpd: Potential SSRF
in mod_rewrite (CVE-2024-39573)

[2.4.37-65]
- Resolves: RHEL-31857 - httpd:2.4/httpd: HTTP response
splitting (CVE-2023-38709)

mod_http2
[1.15.7-10.7]
- Resolves: RHEL-191279 - mod_http2: Apache HTTP Server: Out-of-bounds
Read in mod_headers and mod_mime (CVE-2026-43951)

[1.15.7-10.6]
- Resolves: RHEL-182418 - mod_http2: HTTP/2: Remote Denial of Service via
compression bomb and Slowloris-style attack (CVE-2026-49975)

[1.15.7-10.5]
- Resolves: RHEL-166277 - httpd:2.4/httpd: Apache HTTP Server: HTTP/2 DoS by
Memory Increase (CVE-2025-53020)

[1.15.7-10.4]
- Resolves: RHEL-105186 - httpd:2.4/httpd: untrusted input from a client causes
an assertion to fail in the Apache mod_proxy_http2 module (CVE-2025-49630)

[1.15.7-10.3]
- Resolves: RHEL-58454 - mod_proxy_http2 failures after CVE-2024-38477 fix
- Resolves: RHEL-59017 - random failures in other requests on http/2 stream
when client resets one request

[1.15.7-10.2]
- Resolves: RHEL-71575: Wrong Content-Type when proxying using H2 protocol

[1.15.7-10.1]
- Resolves: RHEL-46214 - Access logs and ErrorDocument don't work when HTTP431
occurs using http/2 on RHEL8

[1.15.7-10]
- Resolves: RHEL-29817 - httpd:2.4/mod_http2: httpd: CONTINUATION frames
DoS (CVE-2024-27316)

[1.15.7-9.3]
- Resolves: RHEL-13367 - httpd:2.4/mod_http2: reset requests exhaust memory
(incomplete fix of CVE-2023-44487)(CVE-2023-45802)

[1.15.7-8.3]
- Resolves: #2177748 - CVE-2023-25690 httpd:2.4/httpd: HTTP request splitting
with mod_rewrite and mod_proxy

mod_md
[1:2.0.8-8.2]
- Resolves: RHEL-134487 - httpd:2.4/httpd: Apache HTTP Server: mod_md (ACME),
unintended retry intervals (CVE-2025-55753)

[1:2.0.8-8]
- Resolves: #1832844 - mod_md does not work with ACME server that does not
provide keyChange or revokeCert resources

[1:2.0.8-7]
- Resolves: #1747912 - add a2md(1) documentation

[1:2.0.8-6]
- Resolves: #1781263 - mod_md ACMEv1 crash

[1:2.0.8-5]
- Resolves: #1747898 - add mod_md package

[1:2.0.8-4]
- require mod_ssl, update package description

[1:2.0.8-3]
- rebuild against 2.4.41

[1:2.0.8-2]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild

[1:2.0.8-1]
- update to 2.0.8

[2.0.3-1]
- Initial import (#1719248).


Related CVEs


CVE-2024-42516
CVE-2026-29169
CVE-2026-34355
CVE-2026-34356
CVE-2026-42536
CVE-2026-43951
CVE-2026-44185
CVE-2026-44186
CVE-2026-44631

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) httpd-2.4.37-65.0.1.module+el8.10.0+90969+a6381771.8.src.rpmccc122bb7df5cda2f50d3bb6e72c1a940e115db7d1094923c9a3c4e4481d146f-ol8_aarch64_appstream
mod_http2-1.15.7-10.module+el8.10.0+90969+a6381771.7.src.rpm3bd5d32140498f721cb0ff65a7b7fdf495ad2433bccdde37e95782f93402873f-ol8_aarch64_appstream
mod_md-2.0.8-8.module+el8.10.0+90899+db89cbcc.2.src.rpm9db8343d602b63ce893a5e6337b5adb88a72fb79432779565626f46e0767998b-ol8_aarch64_appstream
httpd-2.4.37-65.0.1.module+el8.10.0+90969+a6381771.8.aarch64.rpmcd0d36b45644cb58629e2fc07afad6558510a30c94b3a15bcf758d3275b910fa-ol8_aarch64_appstream
httpd-devel-2.4.37-65.0.1.module+el8.10.0+90969+a6381771.8.aarch64.rpm79525f416997bdb9048211f2aea2036203902d384768c05936ad3641715cdae8-ol8_aarch64_appstream
httpd-filesystem-2.4.37-65.0.1.module+el8.10.0+90969+a6381771.8.noarch.rpm42a2644d2fe310d34170223517ce30a2def2ac27e2dd2334fbea47780a7ff94a-ol8_aarch64_appstream
httpd-manual-2.4.37-65.0.1.module+el8.10.0+90969+a6381771.8.noarch.rpm0a94308c03ead36d02fd2dce95964df9e6a63b4f7ddad47be689104e2e32dc0d-ol8_aarch64_appstream
httpd-tools-2.4.37-65.0.1.module+el8.10.0+90969+a6381771.8.aarch64.rpmec7bb4956ea63dcaa43b4fbab40778085ae9082135328fd9699d67beb3e37b3e-ol8_aarch64_appstream
mod_http2-1.15.7-10.module+el8.10.0+90969+a6381771.7.aarch64.rpmf529e3ba81701c78b0636808ab039fb60cb7405079f772184bf9744ee7a1cbd4-ol8_aarch64_appstream
mod_ldap-2.4.37-65.0.1.module+el8.10.0+90969+a6381771.8.aarch64.rpmb66cf84a9e85f48af55e8d777aadec7d3235a6c3dd0fbe5ef9a8d2b789da7c52-ol8_aarch64_appstream
mod_md-2.0.8-8.module+el8.10.0+90899+db89cbcc.2.aarch64.rpm0076c2b3d4031d8b44a8267f229206b5b1a1aa912d18fd0506a11e1441a7fd56-ol8_aarch64_appstream
mod_proxy_html-2.4.37-65.0.1.module+el8.10.0+90969+a6381771.8.aarch64.rpmc7d5ca79df2ec4d8dd322eddce3715ae78311381a827737cc03e9f64b8572499-ol8_aarch64_appstream
mod_session-2.4.37-65.0.1.module+el8.10.0+90969+a6381771.8.aarch64.rpmec76ac260ff19c8cd3160123b3386955e38d24084af4673859b541e223f67eb9-ol8_aarch64_appstream
mod_ssl-2.4.37-65.0.1.module+el8.10.0+90969+a6381771.8.aarch64.rpmbb16aa0584141e0f250c7ebcb38511515bdc16ee84c7c29658d6fafc98ce5764-ol8_aarch64_appstream
Oracle Linux 8 (x86_64) httpd-2.4.37-65.0.1.module+el8.10.0+90969+a6381771.8.src.rpmccc122bb7df5cda2f50d3bb6e72c1a940e115db7d1094923c9a3c4e4481d146f-ol8_x86_64_appstream
mod_http2-1.15.7-10.module+el8.10.0+90969+a6381771.7.src.rpm3bd5d32140498f721cb0ff65a7b7fdf495ad2433bccdde37e95782f93402873f-ol8_x86_64_appstream
mod_md-2.0.8-8.module+el8.10.0+90899+db89cbcc.2.src.rpm9db8343d602b63ce893a5e6337b5adb88a72fb79432779565626f46e0767998b-ol8_x86_64_appstream
httpd-2.4.37-65.0.1.module+el8.10.0+90969+a6381771.8.x86_64.rpmbeddbedf943db6cbe92f5043560f37b5c32669a0bc2c05fe187b039483fd696d-ol8_x86_64_appstream
httpd-devel-2.4.37-65.0.1.module+el8.10.0+90969+a6381771.8.x86_64.rpm6b6478b68564894e98b6e4c6148c0bad383045887fdca0faebaee9f1d41973b0-ol8_x86_64_appstream
httpd-filesystem-2.4.37-65.0.1.module+el8.10.0+90969+a6381771.8.noarch.rpm42a2644d2fe310d34170223517ce30a2def2ac27e2dd2334fbea47780a7ff94a-ol8_x86_64_appstream
httpd-manual-2.4.37-65.0.1.module+el8.10.0+90969+a6381771.8.noarch.rpm0a94308c03ead36d02fd2dce95964df9e6a63b4f7ddad47be689104e2e32dc0d-ol8_x86_64_appstream
httpd-tools-2.4.37-65.0.1.module+el8.10.0+90969+a6381771.8.x86_64.rpmc782fa8915511e1857821e106e43f689bf401f8350cd8fe7e50c99ffeab93134-ol8_x86_64_appstream
mod_http2-1.15.7-10.module+el8.10.0+90969+a6381771.7.x86_64.rpm3107faa0ebdac4776b059f7d4b9ea5fe5eaf7fc7af0ee202885fdbc930f8b2b5-ol8_x86_64_appstream
mod_ldap-2.4.37-65.0.1.module+el8.10.0+90969+a6381771.8.x86_64.rpme4f8a62e24a2075e642d8d028f865bfbad5835ef0844470e524de801fca20a4a-ol8_x86_64_appstream
mod_md-2.0.8-8.module+el8.10.0+90899+db89cbcc.2.x86_64.rpmd840fcfb5901dd6d2d0589f27ddaa733291ebfdd46645f898df94326b1e53f0a-ol8_x86_64_appstream
mod_proxy_html-2.4.37-65.0.1.module+el8.10.0+90969+a6381771.8.x86_64.rpmba5e33c28b82a1a4d7ab5c9e08e67181259f2c14020c0a505343d03ccb3f0468-ol8_x86_64_appstream
mod_session-2.4.37-65.0.1.module+el8.10.0+90969+a6381771.8.x86_64.rpm59524ed9cd91449ae42d23722a9e508cf47b151858539e5d2a159de140273873-ol8_x86_64_appstream
mod_ssl-2.4.37-65.0.1.module+el8.10.0+90969+a6381771.8.x86_64.rpm2d3c55b3cc78d9114fea2146ba85bfd8628c3dd6525f3ba07e42dcb56827839e-ol8_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete