RHSA-2026:42828HighCVSS 7.7

Red Hat Security Advisory: httpd:2.4 security, bug fix, and enhancement update

Published
July 21, 2026
Last Modified
July 24, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2024-42516 — httpd: incomplete fix for CVE-2023-38709 CVE-2026-29169 — httpd: NULL pointer dereference via specially crafted request CVE-2026-34355 — httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass CVE-2026-34356 — httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers CVE-2026-42536 — httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc CVE-2026-43951 — httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime CVE-2026-44185 — httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server CVE-2026-44186 — httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server CVE-2026-44631 — httpd: Apache HTTP Server: Denial of Service via crafted regular expressions

🔗 References (12)