RHSA-2025:13681HighCVSS 7.5

Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.62 SP1 security update

Published
August 14, 2025
Last Modified
September 8, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2024-8176 — libexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat CVE-2024-47252 — httpd: insufficient escaping of user-supplied data in mod_ssl CVE-2025-23048 — httpd: mod_ssl: access control bypass by trusted clients is possible using TLS 1.3 session resumption CVE-2025-32414 — libxml2: Out-of-Bounds Read in libxml2 CVE-2025-32415 — libxml2: Out-of-bounds Read in xmlSchemaIDCFillNodeTables CVE-2025-47947 — modsecurity: ModSecurity Has Possible DoS Vulnerability CVE-2025-49630 — httpd: mod_proxy_http2: untrusted input from a client causes an assertion to fail in the Apache mod_proxy_http2 module CVE-2025-49812 — httpd: HTTP Session Hijack via a TLS upgrade

🎯 Affected products1

  • Red Hat JBoss Core Services 2.4.62.SP1

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link. You must be logged in to download the update. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. Workaround: Do not process untrusted files with the libxml2 library.

🔗 References (12)