Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:0095 - Security Advisory
Issued:
2026-01-06
Updated:
2026-01-06

RHSA-2026:0095 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: httpd security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for httpd is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

  • httpd: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (CVE-2025-58098)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2419365 - CVE-2025-58098 httpd: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...

CVEs

  • CVE-2025-58098

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
httpd-2.4.51-7.el9_0.11.src.rpm SHA-256: 7a8b6e026459867949e73935695694b1ec2a580db502d8afe1435eef1705ec26
ppc64le
httpd-2.4.51-7.el9_0.11.ppc64le.rpm SHA-256: a64429d0ca0ce7f2d1b49d402b32dc9d05d929858d5fb97b8a3bc6a624e20191
httpd-debuginfo-2.4.51-7.el9_0.11.ppc64le.rpm SHA-256: 41cc06950d8fa895fc24e0d1dc47e63b99592d891201a9b0eec3bd773a32fa5b
httpd-debugsource-2.4.51-7.el9_0.11.ppc64le.rpm SHA-256: 702d9b798d8156c161b26a6a1a699a8ff679cf6d4877703e3b73978730c40a2f
httpd-devel-2.4.51-7.el9_0.11.ppc64le.rpm SHA-256: c93d38fa75a3b7440b447c859192871255cf9a6c571dea1e0b819b72ff23bd4a
httpd-filesystem-2.4.51-7.el9_0.11.noarch.rpm SHA-256: 2ce3b117d75c5ada022007d31926fc5c8c7c102fba982c60df21d16dd3a4dbc3
httpd-manual-2.4.51-7.el9_0.11.noarch.rpm SHA-256: 0deec9bb9f7e4dab003a8f63effa55562c89519203ec25e6368ab2c53ab7ab17
httpd-tools-2.4.51-7.el9_0.11.ppc64le.rpm SHA-256: 9594c22b056e5c2abbde71a34785daf976732a12b388c0c20e83155b47e6e93b
httpd-tools-debuginfo-2.4.51-7.el9_0.11.ppc64le.rpm SHA-256: c3625a33dbfeed4fa7ca347f5b4ef6a3cc24b9b573ed0a1319a83c0dc038e0a6
mod_ldap-2.4.51-7.el9_0.11.ppc64le.rpm SHA-256: 980056f12595cd90aa6b9d7f431d4c8d1988530034da1092082855a8cd635f22
mod_ldap-debuginfo-2.4.51-7.el9_0.11.ppc64le.rpm SHA-256: b5af9270550e8985a394cc32e2199bd1a48d36e0c26078b70464c2d3723f9190
mod_lua-2.4.51-7.el9_0.11.ppc64le.rpm SHA-256: 5dbbc8ae27c64c9ad238121ea05d7f143c50d1257c1a689f40abd830c7c76855
mod_lua-debuginfo-2.4.51-7.el9_0.11.ppc64le.rpm SHA-256: f399a7859d80ff3938044df0510f5f22c27b530acaf0be7a43f5bd732a3f2a62
mod_proxy_html-2.4.51-7.el9_0.11.ppc64le.rpm SHA-256: c7d3d946f6b1b28deff05ece40fb5e9aea31dab5158c83923d7488e4918d9ac9
mod_proxy_html-debuginfo-2.4.51-7.el9_0.11.ppc64le.rpm SHA-256: 9fbf5156b6822d823e10c3de1a4e79988376ba690ce1fc0db60f4c2c935134d6
mod_session-2.4.51-7.el9_0.11.ppc64le.rpm SHA-256: 1478d26fcc12cfb790c8c2cf46b3cd2d4d2594183c6111fe99a55531e28c3891
mod_session-debuginfo-2.4.51-7.el9_0.11.ppc64le.rpm SHA-256: cc2556e646e96d19b610e3495d53990e3d9ca68460802ba3f1af809918eec4b0
mod_ssl-2.4.51-7.el9_0.11.ppc64le.rpm SHA-256: 8c02899f201c6483f82e2fba3950240341c6d365a5d06f2c810e4b3794d96727
mod_ssl-debuginfo-2.4.51-7.el9_0.11.ppc64le.rpm SHA-256: ab6531afccc2bb0c98845b8ae9e3d820faf2f67ceab3a9c1d276581c235be94d

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
httpd-2.4.51-7.el9_0.11.src.rpm SHA-256: 7a8b6e026459867949e73935695694b1ec2a580db502d8afe1435eef1705ec26
x86_64
httpd-2.4.51-7.el9_0.11.x86_64.rpm SHA-256: 1749d1f43bd99a3e8198d92f60e1be4532e8ee603389492e7a4da73cd0918456
httpd-debuginfo-2.4.51-7.el9_0.11.x86_64.rpm SHA-256: 484dd4be5ef88c64010a7b843203539117be8cd97cfe201a83efe6b653915382
httpd-debugsource-2.4.51-7.el9_0.11.x86_64.rpm SHA-256: 1021e5e2385c63e3e9136e740a75bd6e62483749aa58e1936c37673c65ed9f06
httpd-devel-2.4.51-7.el9_0.11.x86_64.rpm SHA-256: 3ead5fa6dca4952721c313a3275b0acc901e1934e03f84dbf4980233e463ea86
httpd-filesystem-2.4.51-7.el9_0.11.noarch.rpm SHA-256: 2ce3b117d75c5ada022007d31926fc5c8c7c102fba982c60df21d16dd3a4dbc3
httpd-manual-2.4.51-7.el9_0.11.noarch.rpm SHA-256: 0deec9bb9f7e4dab003a8f63effa55562c89519203ec25e6368ab2c53ab7ab17
httpd-tools-2.4.51-7.el9_0.11.x86_64.rpm SHA-256: 61936f644917edbb8be6f90991f4b3cc011da735a12650b6b496e1d7d3625234
httpd-tools-debuginfo-2.4.51-7.el9_0.11.x86_64.rpm SHA-256: 0b8b32adc4d65de9b3fd2302ee2b74a7d5327d06ababbae6a96a01352ea14873
mod_ldap-2.4.51-7.el9_0.11.x86_64.rpm SHA-256: 78402bf36adc8f2e27aca7d332d2872a6cc0c2c559587a79a2a65f9289ab7001
mod_ldap-debuginfo-2.4.51-7.el9_0.11.x86_64.rpm SHA-256: 1fff413c574e44ba44f484593beca2dc7f8ede9aff0cc225c5ca61a63f4ed575
mod_lua-2.4.51-7.el9_0.11.x86_64.rpm SHA-256: d2ad409d80145602c87e69ea6d40bfa7e4e4a2749e06b8b70330b0977cb47beb
mod_lua-debuginfo-2.4.51-7.el9_0.11.x86_64.rpm SHA-256: 3897b4999f05782a793d58cf09a3efc8c58a9474577737bd1ed5bd03e6d39545
mod_proxy_html-2.4.51-7.el9_0.11.x86_64.rpm SHA-256: 133796ad9059a2ef1c92c537698a18139a8f69c3349d1584526a8826c5b96b40
mod_proxy_html-debuginfo-2.4.51-7.el9_0.11.x86_64.rpm SHA-256: 6a5e9891083bb6964e1788a51db0ba1c3e8d908316aef6a818226da94bcc9a77
mod_session-2.4.51-7.el9_0.11.x86_64.rpm SHA-256: f659cc763bfd611f3087d8fcabced1acccc5898932eeed372ed1799f18e46abc
mod_session-debuginfo-2.4.51-7.el9_0.11.x86_64.rpm SHA-256: 1a138d2400971aaa87aba793e70559be528e7b62738d082c86d67334377d272e
mod_ssl-2.4.51-7.el9_0.11.x86_64.rpm SHA-256: 65605db854c802db70aa2ef4811b980b612ade9b6028afe413452dcebb794ae5
mod_ssl-debuginfo-2.4.51-7.el9_0.11.x86_64.rpm SHA-256: 6eec02162b93c1c9867ae98976748fd365d97b42bdf11df23c253500cc387531

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
httpd-2.4.51-7.el9_0.11.src.rpm SHA-256: 7a8b6e026459867949e73935695694b1ec2a580db502d8afe1435eef1705ec26
aarch64
httpd-2.4.51-7.el9_0.11.aarch64.rpm SHA-256: 7bb7c1b79586ca5ce6c611891753c8a139e789375513f541acb613633c5104c8
httpd-debuginfo-2.4.51-7.el9_0.11.aarch64.rpm SHA-256: c3b2f2b8366d62fd0508940aa157df217f054c0abbfd93afe3901a55965384c9
httpd-debugsource-2.4.51-7.el9_0.11.aarch64.rpm SHA-256: 47dd74828da9342b597bba81c25a20eb306d135ea01c09cdaf06e2a75ba79d33
httpd-devel-2.4.51-7.el9_0.11.aarch64.rpm SHA-256: f259fc418b95dce5104928402b83b1bbd410bdba1e6096836e5feada0d66b381
httpd-filesystem-2.4.51-7.el9_0.11.noarch.rpm SHA-256: 2ce3b117d75c5ada022007d31926fc5c8c7c102fba982c60df21d16dd3a4dbc3
httpd-manual-2.4.51-7.el9_0.11.noarch.rpm SHA-256: 0deec9bb9f7e4dab003a8f63effa55562c89519203ec25e6368ab2c53ab7ab17
httpd-tools-2.4.51-7.el9_0.11.aarch64.rpm SHA-256: e61284079373aad1593b7cfde6cfce6186922a142100d2013b73c4cc0c1a44e1
httpd-tools-debuginfo-2.4.51-7.el9_0.11.aarch64.rpm SHA-256: 699e592ecad6eaeafaec8f2277b3e5339ace01996cdf1d34bb22a583e9fc6da1
mod_ldap-2.4.51-7.el9_0.11.aarch64.rpm SHA-256: dc94e87342e92912e3cd76464ef8a876b4e80d57cbb725d43a3a0b2c2e74b1a1
mod_ldap-debuginfo-2.4.51-7.el9_0.11.aarch64.rpm SHA-256: 4708fec451135ec8ae266820abf6f2b4e49404ef6364a35eeb353fc0c18d7d08
mod_lua-2.4.51-7.el9_0.11.aarch64.rpm SHA-256: afb3b4164a3c096b9d171fcf5c8111bdd2297bb6178924ce55dd86e2c906df5d
mod_lua-debuginfo-2.4.51-7.el9_0.11.aarch64.rpm SHA-256: 4a2a4c724ad8f4a73ffb111051b2a516d34ae0c83f154828eb6f970c2125e0c2
mod_proxy_html-2.4.51-7.el9_0.11.aarch64.rpm SHA-256: f5adda42ab201f0b7b2106db9aa33dd4c931c08aea3217aa1a401443e76108e6
mod_proxy_html-debuginfo-2.4.51-7.el9_0.11.aarch64.rpm SHA-256: c557f2d41c2d70728051523e1073c1ed166ff3e60812e58f37a44f46cfe34314
mod_session-2.4.51-7.el9_0.11.aarch64.rpm SHA-256: 368bab25e68c302f74b12a5170076e74d9f648801ca9c9bd3168f26816a7c89d
mod_session-debuginfo-2.4.51-7.el9_0.11.aarch64.rpm SHA-256: 872ffdf375faee1b32ce1db312a5824d106d936a34751ea9116a22a6c9b7dde1
mod_ssl-2.4.51-7.el9_0.11.aarch64.rpm SHA-256: 90df1f78fa7f214fa5cc62464823bf1f8552fc73caf8ea6af684ff2aab880533
mod_ssl-debuginfo-2.4.51-7.el9_0.11.aarch64.rpm SHA-256: 558afa661c18907d69ef9a8f65891d5a4ce853eb7878794d82cccbe23b992e3c

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
httpd-2.4.51-7.el9_0.11.src.rpm SHA-256: 7a8b6e026459867949e73935695694b1ec2a580db502d8afe1435eef1705ec26
s390x
httpd-2.4.51-7.el9_0.11.s390x.rpm SHA-256: 493626b4f62e84419cb25e48f603efca2ea37b1114693542f472a99e3f404314
httpd-debuginfo-2.4.51-7.el9_0.11.s390x.rpm SHA-256: 6529be062fab2b4f54eeb62fd089cd49a80581c90cee7df36c7228804b58eb89
httpd-debugsource-2.4.51-7.el9_0.11.s390x.rpm SHA-256: de6bab73197fba44f03ddc5ac62e411ae03bcd92a47c6b3128b401704f665839
httpd-devel-2.4.51-7.el9_0.11.s390x.rpm SHA-256: ea57e9de00635a495ceb2acab75a998b3ee9192515823aee45bf40671d20a561
httpd-filesystem-2.4.51-7.el9_0.11.noarch.rpm SHA-256: 2ce3b117d75c5ada022007d31926fc5c8c7c102fba982c60df21d16dd3a4dbc3
httpd-manual-2.4.51-7.el9_0.11.noarch.rpm SHA-256: 0deec9bb9f7e4dab003a8f63effa55562c89519203ec25e6368ab2c53ab7ab17
httpd-tools-2.4.51-7.el9_0.11.s390x.rpm SHA-256: 9e3831a720158243fb68887114ddbce37b8d8fefb61d586fe6372aa93c2acc30
httpd-tools-debuginfo-2.4.51-7.el9_0.11.s390x.rpm SHA-256: 2b101864ef806efa313eedf7c42ec56bfd5cdecbe4357ba45c74a43185283045
mod_ldap-2.4.51-7.el9_0.11.s390x.rpm SHA-256: cc439eea7a1e0bb9d7d6dee6e087d157ffad2c72302bed8ddf3445a9ef723d4e
mod_ldap-debuginfo-2.4.51-7.el9_0.11.s390x.rpm SHA-256: 2a68e559d4d7e7d9cefd9012f3616f1f8c021dc0010feac2d190f63bfe4d5aba
mod_lua-2.4.51-7.el9_0.11.s390x.rpm SHA-256: 3f473ecac4ed6f3536c3b96d944988f422e682fcd7751f78ce9bffd5dfbde5ad
mod_lua-debuginfo-2.4.51-7.el9_0.11.s390x.rpm SHA-256: 4e3c71ddd59e679fcf71529b662d4e07ac31378f7b8f9948b7d0202332452840
mod_proxy_html-2.4.51-7.el9_0.11.s390x.rpm SHA-256: 21da38344c225a0b13afd7e6b52ff825fb315da345292b033e6f966a481a960d
mod_proxy_html-debuginfo-2.4.51-7.el9_0.11.s390x.rpm SHA-256: f15b4da17b09b9ff07516c2080f2f793a98437eb959b1d01aba4b280a8b27d42
mod_session-2.4.51-7.el9_0.11.s390x.rpm SHA-256: c76512bd45c85524a0b27341e1677008f9ae3eb15e354aa2c5f92a3e91e932f1
mod_session-debuginfo-2.4.51-7.el9_0.11.s390x.rpm SHA-256: b16b1a7240378239fa43141dcd96987e26c738412d478096dcaeb6888a8fb358
mod_ssl-2.4.51-7.el9_0.11.s390x.rpm SHA-256: a0795c3894fc0b13a583afbb5fefe46053ff40e7cac6363be81d073bf83b8018
mod_ssl-debuginfo-2.4.51-7.el9_0.11.s390x.rpm SHA-256: 7314e94a8c14f41cfa915e6609847c60809a8f1c57a0504c7043dc6adfe490c0

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility