Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:0075 - Security Advisory
Issued:
2026-01-05
Updated:
2026-01-05

RHSA-2026:0075 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: httpd security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for httpd is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

  • httpd: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (CVE-2025-58098)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le

Fixes

  • BZ - 2419365 - CVE-2025-58098 httpd: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...

CVEs

  • CVE-2025-58098

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - Extended Life Cycle Support 7

SRPM
httpd-2.4.6-99.el7_9.7.src.rpm SHA-256: 9e56fb0032174e4f8274ec7c176f3436f6d9f79fa73f6bb30494bd5948845cfd
x86_64
httpd-2.4.6-99.el7_9.7.x86_64.rpm SHA-256: 6371a3f09a0141299d7bc4015c1b1ca1e199c7202080b73c422077482f88d1ad
httpd-debuginfo-2.4.6-99.el7_9.7.x86_64.rpm SHA-256: e95bae83037ac52aadb6e841cdd4562d9807da01d2739a0365bd07d8fd0b52e6
httpd-debuginfo-2.4.6-99.el7_9.7.x86_64.rpm SHA-256: e95bae83037ac52aadb6e841cdd4562d9807da01d2739a0365bd07d8fd0b52e6
httpd-devel-2.4.6-99.el7_9.7.x86_64.rpm SHA-256: a252fc9e87976c144710ea6d1375ea681a0f9b32720c385863338aad91b5c4b2
httpd-manual-2.4.6-99.el7_9.7.noarch.rpm SHA-256: cd79e60df56e8ef0ef3dbf807ee6cc80b3a264b12794a9dbf0963045db026c0d
httpd-tools-2.4.6-99.el7_9.7.x86_64.rpm SHA-256: 8abf321f2bad04639f0467f2d8b68fa2cc9c0e1184acc81dad73173f05f36683
mod_ldap-2.4.6-99.el7_9.7.x86_64.rpm SHA-256: 1bd3dbb0121c48a0b658fc55260fb2b63b0b24383621ce18401c44cee3227231
mod_proxy_html-2.4.6-99.el7_9.7.x86_64.rpm SHA-256: de2f84c4b63b47ed89713ce06c4c09a688532c9a2d16084989e7e40bea39aa17
mod_session-2.4.6-99.el7_9.7.x86_64.rpm SHA-256: d3b6c5ffc552e824285ada608b9705048e84e0d75146c6ca5474c8b6129fd61e
mod_ssl-2.4.6-99.el7_9.7.x86_64.rpm SHA-256: 00326ea456bee9667591d885edc096f459b74b0d932b23a28d88645dbfb72b96

Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7

SRPM
httpd-2.4.6-99.el7_9.7.src.rpm SHA-256: 9e56fb0032174e4f8274ec7c176f3436f6d9f79fa73f6bb30494bd5948845cfd
s390x
httpd-2.4.6-99.el7_9.7.s390x.rpm SHA-256: 26b90eca01d45678f0d31213d4e066eef85d3891b053dd74f932a94aca1fc00b
httpd-debuginfo-2.4.6-99.el7_9.7.s390x.rpm SHA-256: ffd5c729d38412cd0fc779e34fc3090f4d3edb863ca5d6513d31ca18cf82f67b
httpd-debuginfo-2.4.6-99.el7_9.7.s390x.rpm SHA-256: ffd5c729d38412cd0fc779e34fc3090f4d3edb863ca5d6513d31ca18cf82f67b
httpd-devel-2.4.6-99.el7_9.7.s390x.rpm SHA-256: e8c730d9a365e3657995ff7cce2b53a5453ebd8de544bcdc4995bbbc74620366
httpd-manual-2.4.6-99.el7_9.7.noarch.rpm SHA-256: cd79e60df56e8ef0ef3dbf807ee6cc80b3a264b12794a9dbf0963045db026c0d
httpd-tools-2.4.6-99.el7_9.7.s390x.rpm SHA-256: 024a88fe53278b928f5b9f83d1919cfc5fd346e415898e633df65ece9391a5ae
mod_ldap-2.4.6-99.el7_9.7.s390x.rpm SHA-256: deb9db83cd44cb56a313b8effd2d25d5e89166a345e329e43243f5a9af7c6441
mod_proxy_html-2.4.6-99.el7_9.7.s390x.rpm SHA-256: 15061dad45e871757c183663f5dedfe302a260b967ef87376094b633457357ff
mod_session-2.4.6-99.el7_9.7.s390x.rpm SHA-256: e6b9852a76091626aa5a4bff425d14bb23af88531139499b8a389adfcee521fd
mod_ssl-2.4.6-99.el7_9.7.s390x.rpm SHA-256: 2d4e35b8c808e49482cf403af89dffc145c136b83d368169099f55a5fd071038

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7

SRPM
httpd-2.4.6-99.el7_9.7.src.rpm SHA-256: 9e56fb0032174e4f8274ec7c176f3436f6d9f79fa73f6bb30494bd5948845cfd
ppc64
httpd-2.4.6-99.el7_9.7.ppc64.rpm SHA-256: 9cd62b8a364b548e67c9c8d7445bfd050058e8edb4f70147829cf3c1682df9e5
httpd-debuginfo-2.4.6-99.el7_9.7.ppc64.rpm SHA-256: a84d690b5f865db9e24385507fec3ccea8f2b7b085b56ed2c16cbb828b43c37d
httpd-debuginfo-2.4.6-99.el7_9.7.ppc64.rpm SHA-256: a84d690b5f865db9e24385507fec3ccea8f2b7b085b56ed2c16cbb828b43c37d
httpd-devel-2.4.6-99.el7_9.7.ppc64.rpm SHA-256: 9a2bd40097c58ac1c656200842ea621b7b7f8d8ddcd9e3cdd17b9d34f0bf9841
httpd-manual-2.4.6-99.el7_9.7.noarch.rpm SHA-256: cd79e60df56e8ef0ef3dbf807ee6cc80b3a264b12794a9dbf0963045db026c0d
httpd-tools-2.4.6-99.el7_9.7.ppc64.rpm SHA-256: 51bf0bc0790055da79d539c315d46bf5889c96c92f2a149e9e832e053c76ac43
mod_ldap-2.4.6-99.el7_9.7.ppc64.rpm SHA-256: c7ae61628cc4a96b448e5cdee657dfdf7d83bd7f65b508a7a52e53397333c8cc
mod_proxy_html-2.4.6-99.el7_9.7.ppc64.rpm SHA-256: e4c8c5bfae897376b45da6e25d51405262558b961d65f734ed100ad2b7454f05
mod_session-2.4.6-99.el7_9.7.ppc64.rpm SHA-256: 79133b551d4f12022bd276748272544d9c7672035d66812758f8d53aa0bc56c2
mod_ssl-2.4.6-99.el7_9.7.ppc64.rpm SHA-256: f39ab6164daa3e028444396211a3dcb4f51bed1d9ba192b0b2ddc2706d88e37f

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7

SRPM
httpd-2.4.6-99.el7_9.7.src.rpm SHA-256: 9e56fb0032174e4f8274ec7c176f3436f6d9f79fa73f6bb30494bd5948845cfd
ppc64le
httpd-2.4.6-99.el7_9.7.ppc64le.rpm SHA-256: a8ba6df106f55c290da28086315a5981bf1247871e7bf6530238e8e9d879f61d
httpd-debuginfo-2.4.6-99.el7_9.7.ppc64le.rpm SHA-256: f3400b198f18ed84d2e82d9946f332c07ead4a3867249b1a812635b6198de24f
httpd-debuginfo-2.4.6-99.el7_9.7.ppc64le.rpm SHA-256: f3400b198f18ed84d2e82d9946f332c07ead4a3867249b1a812635b6198de24f
httpd-devel-2.4.6-99.el7_9.7.ppc64le.rpm SHA-256: 283a704dea55a2fab569468a4558da944cc69e425730643dbc88d88e238f94fd
httpd-manual-2.4.6-99.el7_9.7.noarch.rpm SHA-256: cd79e60df56e8ef0ef3dbf807ee6cc80b3a264b12794a9dbf0963045db026c0d
httpd-tools-2.4.6-99.el7_9.7.ppc64le.rpm SHA-256: 44529077203bcfe9b8999cc59e9f73494f2ac5b23a225389ff932f3302e70bee
mod_ldap-2.4.6-99.el7_9.7.ppc64le.rpm SHA-256: 01a30ba5deabe32836765f39d797b120b2d2d7ad1f33fd8f45bd173e8a2039a3
mod_proxy_html-2.4.6-99.el7_9.7.ppc64le.rpm SHA-256: cf49e1e4eaf2f5569a423690a8279db4c3076ac2766a75ba163d512cd89a0651
mod_session-2.4.6-99.el7_9.7.ppc64le.rpm SHA-256: 6904bdcf90a90ef6a222df23a752bc5a5fb552c73889256ea7c67ad3c79240bc
mod_ssl-2.4.6-99.el7_9.7.ppc64le.rpm SHA-256: e56082778ad6fd9919452bedcd577237445550dc9acedc1e462cacb154b92d09

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility