RHSA-2026:50538: Important: mod_http2 security update
Important: modhttp2 security update
Other sources
The modh2 Apache httpd module implements the HTTP2 protocol (h2+h2c) on top of libnghttp2 for httpd 2.4 servers.Security Fix(es): modhttp2: Apache HTTP Server: HTTP/2 DoS by Memory Increase (CVE-2025-53020) httpd: httpd: HTTP/2 Remote Denial of Service via compression bomb and Slowloris-style attack (CVE-2026-49975) httpd: modhttp2: Apache HTTP Server modhttp2: Use After Free vulnerability allows arbitrary code execution or denial of service. (CVE-2026-48913) httpd: Apache HTTP Server: Out-of-bounds Read in modheaders and modmime (CVE-2026-43951) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:50538?
The severity of RHSA-2026:50538 is classified as high with a score of 7.
What security issues does RHSA-2026:50538 address?
RHSA-2026:50538 addresses a remote denial of service vulnerability in the mod_http2 component of Apache HTTP Server.
How do I fix RHSA-2026:50538?
To fix RHSA-2026:50538, you should update the mod_http2 module on your Apache HTTP Server to the latest version provided by Red Hat.
Which systems are affected by RHSA-2026:50538?
RHSA-2026:50538 affects multiple versions of Red Hat Enterprise Linux, including those for IBM z Systems, Power, and x86_64 architectures.
What could happen if RHSA-2026:50538 is not addressed?
If RHSA-2026:50538 is not addressed, the vulnerability could lead to a denial of service attack, potentially causing service interruptions.