RHSA-2026:36373: Important: httpd:2.4 security update
Important: httpd:2.4 security update
Other sources
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.Security Fix(es): httpd: Apache HTTP Server: HTTP/2 DoS by Memory Increase (CVE-2025-53020) httpd: modproxyajp: heap-based buffer over-read and memory disclosure in ajpparsedata() (CVE-2026-34059) httpd: modproxyajp: heap-based buffer over-read due to missing null-termination check (CVE-2026-34032) httpd: modproxyajp: off-by-one out-of-bounds reads in AJP getter functions (CVE-2026-33857) httpd: modauthnsocache: NULL pointer dereference can cause a child process crash (CVE-2026-33007) Apache HTTP Server: modproxyajp: Apache HTTP Server modproxyajp: Arbitrary code execution via heap-based buffer overflow (CVE-2026-28780) httpd: HTTP/2: Remote Denial of Service via compression bomb and Slowloris-style attack (CVE-2026-49975) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-56.module+el8.8.0+24497+e470c0e2.12 - Upgrade
Upgrade
redhat/httpd-filesystemto a version that resolves this vulnerability.Fixed in 2.4.37-56.module+el8.8.0+24497+e470c0e2.12 - Upgrade
Upgrade
redhat/httpd-manualto a version that resolves this vulnerability.Fixed in 2.4.37-56.module+el8.8.0+24497+e470c0e2.12 - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-56.module+el8.8.0+24497+e470c0e2.12 - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-56.module+el8.8.0+24497+e470c0e2.12 - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-56.module+el8.8.0+24497+e470c0e2.12 - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-56.module+el8.8.0+24497+e470c0e2.12 - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-56.module+el8.8.0+24497+e470c0e2.12 - Upgrade
Upgrade
httpdto a version that resolves this vulnerability.Fixed in 2.4.37-56.module+el8.8.0+24497+e470c0e2.12 - Upgrade
Upgrade
mod_http2to a version that resolves this vulnerability.Fixed in 1.15.7-8.module+el8.8.0+24497+e470c0e2.7 - Upgrade
Upgrade
mod_ldapto a version that resolves this vulnerability.Fixed in 2.4.37-56.module+el8.8.0+24497+e470c0e2.12 - Upgrade
Upgrade
mod_mdto a version that resolves this vulnerability.Fixed in 2.0.8-8.module+el8.8.0+23840+d7e7db80.1 - Upgrade
Upgrade
mod_proxy_htmlto a version that resolves this vulnerability.Fixed in 2.4.37-56.module+el8.8.0+24497+e470c0e2.12 - Upgrade
Upgrade
mod_sessionto a version that resolves this vulnerability.Fixed in 2.4.37-56.module+el8.8.0+24497+e470c0e2.12 - Upgrade
Upgrade
mod_sslto a version that resolves this vulnerability.Fixed in 2.4.37-56.module+el8.8.0+24497+e470c0e2.12
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:36373?
The severity of RHSA-2026:36373 is classified as high, with a CVSS score of 7.
How do I fix RHSA-2026:36373?
To fix RHSA-2026:36373, update your httpd packages to the latest version provided by Red Hat.
What are the main vulnerabilities addressed in RHSA-2026:36373?
RHSA-2026:36373 addresses vulnerabilities such as a HTTP/2 Denial of Service due to memory increase and mod_proxy_ajp heap-based buffer over-read.
Which software is affected by RHSA-2026:36373?
RHSA-2026:36373 affects several Red Hat httpd packages including redhat/httpd and redhat/httpd-tools.
Is a reboot required after applying the fix for RHSA-2026:36373?
A reboot is not typically required after applying the fix for RHSA-2026:36373, but verify your application's stability post-update.