Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:36831 - Security Advisory
Issued:
2026-07-08
Updated:
2026-07-08

RHSA-2026:36831 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: httpd:2.4 security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for the httpd:2.4 module is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

  • httpd: Apache HTTP Server: HTTP/2 DoS by Memory Increase (CVE-2025-53020)
  • httpd: mod_proxy_ajp: heap-based buffer over-read and memory disclosure in ajp_parse_data() (CVE-2026-34059)
  • httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check (CVE-2026-34032)
  • httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions (CVE-2026-33857)
  • httpd: mod_authn_socache: NULL pointer dereference can cause a child process crash (CVE-2026-33007)
  • Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow (CVE-2026-28780)
  • httpd: HTTP/2: Remote Denial of Service via compression bomb and Slowloris-style attack (CVE-2026-49975)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.6 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.6 x86_64

Fixes

  • BZ - 2379343 - CVE-2025-53020 mod_http2: Apache HTTP Server: HTTP/2 DoS by Memory Increase
  • BZ - 2464940 - CVE-2026-34059 httpd: mod_proxy_ajp: heap-based buffer over-read and memory disclosure in ajp_parse_data()
  • BZ - 2464952 - CVE-2026-34032 httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check
  • BZ - 2464953 - CVE-2026-33857 httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions
  • BZ - 2465299 - CVE-2026-33007 httpd: mod_authn_socache: NULL pointer dereference can cause a child process crash
  • BZ - 2466913 - CVE-2026-28780 Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow
  • BZ - 2485371 - CVE-2026-49975 httpd: HTTP/2: Remote Denial of Service via compression bomb and Slowloris-style attack

CVEs

  • CVE-2025-53020
  • CVE-2026-28780
  • CVE-2026-33007
  • CVE-2026-33857
  • CVE-2026-34032
  • CVE-2026-34059
  • CVE-2026-49975

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.6

SRPM
httpd-2.4.37-47.module+el8.6.0+24496+af8fe930.13.src.rpm SHA-256: ce09fca789b98f7ced97eb0c72dbbd88983ccd0c1fecbc9979e4a51c3dcc4e58
mod_http2-1.15.7-5.module+el8.6.0+24496+af8fe930.5.src.rpm SHA-256: 4a53e563f40e78c69718c2232782861218ddca54627f8296c3e5940aed23cafb
mod_md-2.0.8-8.module+el8.6.0+23843+c27a5dc4.1.src.rpm SHA-256: 65e9a5d8b715956613dc0edd09f1c0bbb0ade792b51e0e835746c30b142f4d4d
x86_64
httpd-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: b316cfaab2e6b0668f8fd3226c1abf63cbb9cb25dc2331621eaa36e98ba959c7
httpd-debuginfo-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: d88607d132e7f55d453e2196c7860172c26a5499bc2ba6638654ff4d89bb5bd2
httpd-debugsource-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: deec76c47da34bfca60a040d956c0e93c19c790dbefd2fc05e64dcd6afed13d7
httpd-devel-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: ebc63ebe475fbda32345a849cee2d44722d13e2796347c59a26e29d665f30e88
httpd-filesystem-2.4.37-47.module+el8.6.0+24496+af8fe930.13.noarch.rpm SHA-256: f40a93f9e6f39793d5a2686e9a923ead32c3b2b2b8f6feeb5de4e558aa8ef409
httpd-manual-2.4.37-47.module+el8.6.0+24496+af8fe930.13.noarch.rpm SHA-256: f310a015b4fdc7a8f8e2bb552d33f9da7080384172f6177ee3fcaab8a441443d
httpd-tools-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: c12287789d54cfe6afc1f6b02a70c4bb555becc8630da8b0206c0ba2b612dab4
httpd-tools-debuginfo-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: 9946fa33d4f93140e3bbe8491b5b1e2305f65ee56ceb4c78a1b339437a321a5b
mod_http2-1.15.7-5.module+el8.6.0+24496+af8fe930.5.x86_64.rpm SHA-256: 3f8b56af0a6f70e4b34b303ea99a386a9f31394019745618f554b3cb84acd81e
mod_http2-debuginfo-1.15.7-5.module+el8.6.0+24496+af8fe930.5.x86_64.rpm SHA-256: f8cf1f25cd87475080ac09c08af8acf1003ecb5e9d1076cad82cfc4f12d59ce0
mod_http2-debugsource-1.15.7-5.module+el8.6.0+24496+af8fe930.5.x86_64.rpm SHA-256: 0d800b0d4194da4c49d91e4d9ee895be42fab463c1e6c558c1d475bbc956616d
mod_ldap-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: a66ca86ea47d4fb145ee6788bb8f9df0e461ce4ed6fdbdb2d45a6377ea6a74d2
mod_ldap-debuginfo-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: 74ad7911e72256ca18391a970e44b428976aa0fbc6cb5354982d6cd972ad1e5e
mod_md-2.0.8-8.module+el8.6.0+23843+c27a5dc4.1.x86_64.rpm SHA-256: 0f1ceace516565854cef20d9dd1dde40b556c43627a4e01fc06cfe198a1024aa
mod_md-debuginfo-2.0.8-8.module+el8.6.0+23843+c27a5dc4.1.x86_64.rpm SHA-256: 2a78141f88fcdf7c768c2b7251f24903b4a14c9f18f305c14640c92e81f8c543
mod_md-debugsource-2.0.8-8.module+el8.6.0+23843+c27a5dc4.1.x86_64.rpm SHA-256: 15e7c3f43f88079e50565fda36b9012aebefc5872c0af65bc3517143d6ebc394
mod_proxy_html-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: 4ffec9a12fd61d53d8d9fcb0ba32fdda4653e8763bce8428b6983fed52fd28c1
mod_proxy_html-debuginfo-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: 6d3e166045d31da7541867510c1f10e5be6fdc3b583a76f72733d9e26c807206
mod_session-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: 992205c912b01c8c152cb9063f2d007d484ba4042e2d26f44397e224d621e283
mod_session-debuginfo-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: d20c44fe385b7f162fc4ff86e24f2b182b7b053ee834beeeacc0023e4eb9a17e
mod_ssl-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: 1619fd7a1ab09cc74f12f21f1a5f69ed508dbe6835d7db8c037be2b46465ef86
mod_ssl-debuginfo-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: 2295cbd3d12521c24a7780f82ffb2c00aa09015e9619aee2a18628098a32b4a0

Red Hat Enterprise Linux Server - AUS 8.6

SRPM
httpd-2.4.37-47.module+el8.6.0+24496+af8fe930.13.src.rpm SHA-256: ce09fca789b98f7ced97eb0c72dbbd88983ccd0c1fecbc9979e4a51c3dcc4e58
mod_http2-1.15.7-5.module+el8.6.0+24496+af8fe930.5.src.rpm SHA-256: 4a53e563f40e78c69718c2232782861218ddca54627f8296c3e5940aed23cafb
mod_md-2.0.8-8.module+el8.6.0+23843+c27a5dc4.1.src.rpm SHA-256: 65e9a5d8b715956613dc0edd09f1c0bbb0ade792b51e0e835746c30b142f4d4d
x86_64
httpd-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: b316cfaab2e6b0668f8fd3226c1abf63cbb9cb25dc2331621eaa36e98ba959c7
httpd-debuginfo-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: d88607d132e7f55d453e2196c7860172c26a5499bc2ba6638654ff4d89bb5bd2
httpd-debugsource-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: deec76c47da34bfca60a040d956c0e93c19c790dbefd2fc05e64dcd6afed13d7
httpd-devel-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: ebc63ebe475fbda32345a849cee2d44722d13e2796347c59a26e29d665f30e88
httpd-filesystem-2.4.37-47.module+el8.6.0+24496+af8fe930.13.noarch.rpm SHA-256: f40a93f9e6f39793d5a2686e9a923ead32c3b2b2b8f6feeb5de4e558aa8ef409
httpd-manual-2.4.37-47.module+el8.6.0+24496+af8fe930.13.noarch.rpm SHA-256: f310a015b4fdc7a8f8e2bb552d33f9da7080384172f6177ee3fcaab8a441443d
httpd-tools-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: c12287789d54cfe6afc1f6b02a70c4bb555becc8630da8b0206c0ba2b612dab4
httpd-tools-debuginfo-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: 9946fa33d4f93140e3bbe8491b5b1e2305f65ee56ceb4c78a1b339437a321a5b
mod_http2-1.15.7-5.module+el8.6.0+24496+af8fe930.5.x86_64.rpm SHA-256: 3f8b56af0a6f70e4b34b303ea99a386a9f31394019745618f554b3cb84acd81e
mod_http2-debuginfo-1.15.7-5.module+el8.6.0+24496+af8fe930.5.x86_64.rpm SHA-256: f8cf1f25cd87475080ac09c08af8acf1003ecb5e9d1076cad82cfc4f12d59ce0
mod_http2-debugsource-1.15.7-5.module+el8.6.0+24496+af8fe930.5.x86_64.rpm SHA-256: 0d800b0d4194da4c49d91e4d9ee895be42fab463c1e6c558c1d475bbc956616d
mod_ldap-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: a66ca86ea47d4fb145ee6788bb8f9df0e461ce4ed6fdbdb2d45a6377ea6a74d2
mod_ldap-debuginfo-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: 74ad7911e72256ca18391a970e44b428976aa0fbc6cb5354982d6cd972ad1e5e
mod_md-2.0.8-8.module+el8.6.0+23843+c27a5dc4.1.x86_64.rpm SHA-256: 0f1ceace516565854cef20d9dd1dde40b556c43627a4e01fc06cfe198a1024aa
mod_md-debuginfo-2.0.8-8.module+el8.6.0+23843+c27a5dc4.1.x86_64.rpm SHA-256: 2a78141f88fcdf7c768c2b7251f24903b4a14c9f18f305c14640c92e81f8c543
mod_md-debugsource-2.0.8-8.module+el8.6.0+23843+c27a5dc4.1.x86_64.rpm SHA-256: 15e7c3f43f88079e50565fda36b9012aebefc5872c0af65bc3517143d6ebc394
mod_proxy_html-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: 4ffec9a12fd61d53d8d9fcb0ba32fdda4653e8763bce8428b6983fed52fd28c1
mod_proxy_html-debuginfo-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: 6d3e166045d31da7541867510c1f10e5be6fdc3b583a76f72733d9e26c807206
mod_session-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: 992205c912b01c8c152cb9063f2d007d484ba4042e2d26f44397e224d621e283
mod_session-debuginfo-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: d20c44fe385b7f162fc4ff86e24f2b182b7b053ee834beeeacc0023e4eb9a17e
mod_ssl-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: 1619fd7a1ab09cc74f12f21f1a5f69ed508dbe6835d7db8c037be2b46465ef86
mod_ssl-debuginfo-2.4.37-47.module+el8.6.0+24496+af8fe930.13.x86_64.rpm SHA-256: 2295cbd3d12521c24a7780f82ffb2c00aa09015e9619aee2a18628098a32b4a0

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility