Security update: Apache httpd 2.4.69 RPM and DEB packages with HTTP/2, HTTP/3, Brotli, TLS 1.3, OpenSSL 4.0.3 and ALPN for EL7/EL8/EL9/EL10, Ubuntu 22.04/24.04

Apache httpd 2.4.69 has been added to the CodeIT repository, built with HTTP/2 (mod_http2), Brotli, TLS 1.3 and ALPN, against OpenSSL 4.0.3. The packages are built for RHEL, CentOS, AlmaLinux, Rocky Linux and Oracle Linux 7, 8, 9 and 10, and for Ubuntu 22.04 and 24.04.

This update fixes security vulnerabilities. Upgrading is recommended.

From 2.4.69 on, mod_ssl is built against the OpenSSL 3.0 API instead of 1.1.1 (OPENSSL_API_COMPAT raised from 1.1.1 to 3.0.0), because OpenSSL 4.0 removes features that were deprecated before 3.0. SRP (TLS-SRP, RFC 5054) goes with it: the SSLSRPVerifierFile and SSLSRPUnknownUserSeed directives no longer exist, so remove them from your configuration before upgrading or httpd will not start, and the SSL_SRP_USER and SSL_SRP_USERINFO variables are no longer set. The ENGINE API was already disabled in these packages.

mod_http2 in the RPM packages is now built from the httpd source tree, the way the DEB packages and Ubuntu’s own apache2 already do, instead of from the separate mod_h2 project. The package keeps its name, mod_http2, and now carries the httpd version, so dnf or yum upgrade from mod_http2 2.0.42 to it on their own: nothing has to be removed first, and an edited 10-h2.conf is kept.

HTTP/3 is available for this httpd through mod_http3, an experimental module packaged separately:

  • RPM, EL8 and later: dnf install mod_http3
  • RPM, EL7: yum install mod_http3
  • DEB: apt install libapache2-mod-http3

The module is loaded as soon as it is installed; HTTP/3 itself is enabled per virtual host. Edit the example vhost the package installs (ServerName and certificate): on EL it is /etc/httpd/vhosts.d/http3-vhost.conf, which httpd.conf does not include by default, so add IncludeOptional vhosts.d/*.conf; on Ubuntu run a2ensite http3-vhost. Then reload httpd and open 443/udp in the firewall, since QUIC runs over UDP.

Major changes:

  • Fix the tar icon in the documentation so that its background is transparent. PR 70238.
  • mod_ssl: Fix OpenSSL compatibility macros for X509_get0_notBefore, X509_get0_notAfter, and X509_get0_serialNumber with OpenSSL < 1.1. PR 70205.
  • mod_cgid, mod_ssl, mod_md: Various hardening fixes.
  • mod_md: MDServerStatus is now disabled by default.
  • mod_auth_digest: Fix compatibility with expression-based AuthName. PR 59039.
  • mod_auth_digest.c: Drop RFC 2069 support; rewrite shared memory handling and client nonce handling; “authdigest-opaque” mutex is now longer needed.
  • mod_lbmethod_heartbeat: Use safe integer parsing with range validation, replacing atoi().
  • core: Reject control characters in the reason phrase of interim responses. Only accept space as status-code separator.
  • mod_substitute: Fix SubstituteMaxLineLength to reject values too large for the K/M/G suffix.
  • mod_substitute: Fix crash or misbehaviour when loading a Substitute directive with a missing closing delimiter.
  • mod_dir: Fix a crash in fixup_dir for a request not mapped to any type. PR68527.
  • mod_http2: Do not drop an in-flight response when a client sends a graceful GOAWAY (error code 0) while streams it opened are still being processed. The session now drains open streams instead of tearing down immediately, which async MPMs hit far more than event. Fixes a silently dropped response; RFC 9113 compliant.
  • mod_md: OpenSSL 4 compatibility.
  • pytest_suite: Port of the old PERL test framework to Python and pytest. Now included in the source tree under ./test

Fixed vulnerabilities:

  • SECURITY: CVE-2026-93546: mod_dav_fs namespace overflow Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory’s property database via PROPPATCH requests declaring many XML namespaces.
  • SECURITY: CVE-2026-79768: mod_userdir information disclosure Path equivalence: ‘/./’ (single dot directory) vulnerability in Apache HTTP Server’s mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-73637: mod_auth_digest DoS attack Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
  • SECURITY: CVE-2026-73636: mod_auth_digest one-time-nonce replay attack Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client’s shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
  • SECURITY: CVE-2026-63718: mod_proxy_uwsgi Transfer-Encoding response smuggling Inconsistent Interpretation of HTTP Requests (‘HTTP Request/Response Smuggling’) response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68.
  • SECURITY: CVE-2026-63686: mod_xml2enc crash on charset conversion failure A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
  • SECURITY: CVE-2026-63292: mod_vhost_alias stack overflow Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
  • SECURITY: CVE-2026-63045: mod_proxy_ftp PASV address handling Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
  • SECURITY: CVE-2026-59797: mod_ssl SSLRequire allows .htaccess ap_expr file-function Improper Privilege Management vulnerability in Apache HTTP Server’s mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-59685: Out-of-Bounds Write in ap_directory_walk() Canonical-Name Rewrite on CASE_BLIND_FILESYSTEM Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-58415: mod_dav_fs property database read access Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-57941: mod_http2 use-after-free / wild write via shared session->bbtmp re-entrancy Use After Free vulnerability in Apache HTTP Server’s mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-56449: mod_proxy_html: crash in dump_content Out-of-bounds Write vulnerability in Apache HTTP Server’s mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-56154: mod_rewrite use-after-free via %{LA-U:HTTP…} Use After Free vulnerability in Apache HTTP Server’s mod_rewrite when using lookahead (%{LA-U:HTTP…}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-56153: mod_charset_lite: Heap overflow in finish_partial_char Out-of-bounds Write vulnerability in Apache HTTP Server’s mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-48005: mod_auth_digest reauthentication attack Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
  • SECURITY: CVE-2026-47360: mod_session: Session cookie not removed during internal redirect Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server’s mod_session_cookie module.
  • SECURITY: CVE-2026-46729: mod_heartmonitor denial of service NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-42528: mod_dav shared lock overflow A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes. Users are recommended to upgrade to version 2.4.69, which fixes this issue
  • SECURITY: CVE-2026-42356: limited RCE for some internal redirects to non-CGI files in CGI directories Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.

Leave a Reply

Your email address will not be published. Required fields are marked *