Security update: Apache httpd 2.4.69 RPM and DEB packages with HTTP/2, HTTP/3, Brotli, TLS 1.3, OpenSSL 4.0.3 and ALPN for EL7/EL8/EL9/EL10, Ubuntu 22.04/24.04

Apache httpd 2.4.69 has been added to the CodeIT repository, built with HTTP/2 (mod_http2), Brotli, TLS 1.3 and ALPN, against OpenSSL 4.0.3. The packages are built for RHEL, CentOS, AlmaLinux, Rocky Linux and Oracle Linux 7, 8, 9 and 10, and for Ubuntu 22.04 and 24.04.

This update fixes security vulnerabilities. Upgrading is recommended.

From 2.4.69 on, mod_ssl is built against the OpenSSL 3.0 API instead of 1.1.1 (OPENSSL_API_COMPAT raised from 1.1.1 to 3.0.0), because OpenSSL 4.0 removes features that were deprecated before 3.0. SRP (TLS-SRP, RFC 5054) goes with it: the SSLSRPVerifierFile and SSLSRPUnknownUserSeed directives no longer exist, so remove them from your configuration before upgrading or httpd will not start, and the SSL_SRP_USER and SSL_SRP_USERINFO variables are no longer set. The ENGINE API was already disabled in these packages.

mod_http2 in the RPM packages is now built from the httpd source tree, the way the DEB packages and Ubuntu’s own apache2 already do, instead of from the separate mod_h2 project. The package keeps its name, mod_http2, and now carries the httpd version, so dnf or yum upgrade from mod_http2 2.0.42 to it on their own: nothing has to be removed first, and an edited 10-h2.conf is kept.

HTTP/3 is available for this httpd through mod_http3, an experimental module packaged separately:

  • RPM, EL8 and later: dnf install mod_http3
  • RPM, EL7: yum install mod_http3
  • DEB: apt install libapache2-mod-http3

The module is loaded as soon as it is installed; HTTP/3 itself is enabled per virtual host. Edit the example vhost the package installs (ServerName and certificate): on EL it is /etc/httpd/vhosts.d/http3-vhost.conf, which httpd.conf does not include by default, so add IncludeOptional vhosts.d/*.conf; on Ubuntu run a2ensite http3-vhost. Then reload httpd and open 443/udp in the firewall, since QUIC runs over UDP.

Major changes:

  • Fix the tar icon in the documentation so that its background is transparent. PR 70238.
  • mod_ssl: Fix OpenSSL compatibility macros for X509_get0_notBefore, X509_get0_notAfter, and X509_get0_serialNumber with OpenSSL < 1.1. PR 70205.
  • mod_cgid, mod_ssl, mod_md: Various hardening fixes.
  • mod_md: MDServerStatus is now disabled by default.
  • mod_auth_digest: Fix compatibility with expression-based AuthName. PR 59039.
  • mod_auth_digest.c: Drop RFC 2069 support; rewrite shared memory handling and client nonce handling; “authdigest-opaque” mutex is now longer needed.
  • mod_lbmethod_heartbeat: Use safe integer parsing with range validation, replacing atoi().
  • core: Reject control characters in the reason phrase of interim responses. Only accept space as status-code separator.
  • mod_substitute: Fix SubstituteMaxLineLength to reject values too large for the K/M/G suffix.
  • mod_substitute: Fix crash or misbehaviour when loading a Substitute directive with a missing closing delimiter.
  • mod_dir: Fix a crash in fixup_dir for a request not mapped to any type. PR68527.
  • mod_http2: Do not drop an in-flight response when a client sends a graceful GOAWAY (error code 0) while streams it opened are still being processed. The session now drains open streams instead of tearing down immediately, which async MPMs hit far more than event. Fixes a silently dropped response; RFC 9113 compliant.
  • mod_md: OpenSSL 4 compatibility.
  • pytest_suite: Port of the old PERL test framework to Python and pytest. Now included in the source tree under ./test

Fixed vulnerabilities:

  • SECURITY: CVE-2026-93546: mod_dav_fs namespace overflow Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory’s property database via PROPPATCH requests declaring many XML namespaces.
  • SECURITY: CVE-2026-79768: mod_userdir information disclosure Path equivalence: ‘/./’ (single dot directory) vulnerability in Apache HTTP Server’s mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-73637: mod_auth_digest DoS attack Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
  • SECURITY: CVE-2026-73636: mod_auth_digest one-time-nonce replay attack Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client’s shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
  • SECURITY: CVE-2026-63718: mod_proxy_uwsgi Transfer-Encoding response smuggling Inconsistent Interpretation of HTTP Requests (‘HTTP Request/Response Smuggling’) response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68.
  • SECURITY: CVE-2026-63686: mod_xml2enc crash on charset conversion failure A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
  • SECURITY: CVE-2026-63292: mod_vhost_alias stack overflow Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
  • SECURITY: CVE-2026-63045: mod_proxy_ftp PASV address handling Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
  • SECURITY: CVE-2026-59797: mod_ssl SSLRequire allows .htaccess ap_expr file-function Improper Privilege Management vulnerability in Apache HTTP Server’s mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-59685: Out-of-Bounds Write in ap_directory_walk() Canonical-Name Rewrite on CASE_BLIND_FILESYSTEM Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-58415: mod_dav_fs property database read access Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-57941: mod_http2 use-after-free / wild write via shared session->bbtmp re-entrancy Use After Free vulnerability in Apache HTTP Server’s mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-56449: mod_proxy_html: crash in dump_content Out-of-bounds Write vulnerability in Apache HTTP Server’s mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-56154: mod_rewrite use-after-free via %{LA-U:HTTP…} Use After Free vulnerability in Apache HTTP Server’s mod_rewrite when using lookahead (%{LA-U:HTTP…}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-56153: mod_charset_lite: Heap overflow in finish_partial_char Out-of-bounds Write vulnerability in Apache HTTP Server’s mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-48005: mod_auth_digest reauthentication attack Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
  • SECURITY: CVE-2026-47360: mod_session: Session cookie not removed during internal redirect Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server’s mod_session_cookie module.
  • SECURITY: CVE-2026-46729: mod_heartmonitor denial of service NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-42528: mod_dav shared lock overflow A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes. Users are recommended to upgrade to version 2.4.69, which fixes this issue
  • SECURITY: CVE-2026-42356: limited RCE for some internal redirects to non-CGI files in CGI directories Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.

Security update: openssl 4.0.3 RPM and DEB packages released

openssl 4.0.3 has been added to the CodeIT repository. The packages are built for RHEL, CentOS, AlmaLinux, Rocky Linux and Oracle Linux 7, 8, 9 and 10, and for Ubuntu 22.04 and 24.04.

This update fixes security vulnerabilities. Upgrading is recommended.

Major changes:

  • OpenSSL 4.0.3 is a security patch release. The most severe CVE fixed in this release is High.
  • This release incorporates the following bug fixes and mitigations:
  • Fixed a bug where `EVP_DecryptFinal()` incorrectly reported a stale success on AES-SIV authentication failure.
  • Fixed a regression in base64 encoding BIO filter introduced in OpenSSL 4.0 where incomplete writes down the BIO chain may result in the loss of encoded base64 data.

Fixed vulnerabilities:

  • Fixed DTLS retransmissions of handshake messages from a stale buffer offset. (CVE-2026-84782)
  • Fixed a use-after-free in X.509 extension cache under concurrent use. (CVE-2026-84783)
  • Fixed excessive memory allocation in relative CRLDP processing. (CVE-2026-35189)
  • Fixed QUIC unvalidated amplification credit may be over-accounted. (CVE-2026-35191)
  • Fixed potential CPU DoS via O(n^2) fragment reassembly in QUIC. (CVE-2026-42772)
  • Fixed a timing side-channel in scalar multiplication for mon-NIST EC curves. (CVE-2026-54872)
  • Fixed QUIC `STREAM` fragment metadata DoS. (CVE-2026-54873)
  • Fixed non-constant-time SM2 scalar multiplication on ARM64 and RISC-V. (CVE-2026-54875)
  • Fixed out-of-bounds access after `SSL_set_SSL_CTX()` during a handshake. (CVE-2026-72897)
  • Fixed QUIC connection-level flow control was not enforced for streams. (CVE-2026-75804)
  • Fixed a NULL pointer dereference in CMP client revocation response handling. (CVE-2026-75805)
  • Fixed an unauthenticated and undersized DTLS 1.2 AEAD record causing DoS. (CVE-2026-75806)
  • Fixed a timing side-channel in SM2 signature generation. (CVE-2026-77696)
  • Fixed an unbounded `RETIRE_CONNECTION_ID` backlog in QUIC stack implementation. (CVE-2026-84784)

The libraries with QUIC support are still shipped as a separate, non-conflicting openssl-quic-libs package, with its own .so.81.4 suffix, so that they cannot clash with the official .so.X.

Security update: NGINX 1.31.6 Mainline RPM and DEB packages with HTTP/3, Brotli, TLS 1.3 and OpenSSL 4.0.2 for EL7/EL8/EL9/EL10, Ubuntu 22.04/24.04

nginx 1.31.6 Mainline with HTTP/3 support has been added to the CodeIT repository. http2 and ngx_cache_purge are built in, and OpenSSL is linked dynamically against the official OpenSSL 4.0.2 with QUIC support. The Brotli compression module from Google and ngx_http_geoip2 ship as dynamic modules, in nginx-module-brotli and nginx-module-geoip2, which the nginx rpm pulls in automatically (kept as a dependency so that existing installations upgrade without losing those directives; it will be dropped in a few months, and both modules then become truly optional). The packages are built for RHEL, CentOS, AlmaLinux, Rocky Linux and Oracle Linux 7, 8, 9 and 10, and for Ubuntu 22.04 and 24.04.

This update fixes security vulnerabilities. Upgrading is recommended.

More dynamic modules are packaged alongside and are optional: nginx-module-lua with lua-resty-core and lua-resty-lrucache, nginx-module-acme for automatic ACMEv2 certificates, nginx-module-njs, nginx-module-perl, nginx-module-xslt and nginx-module-image-filter. Each one ships its own load_module line in /etc/nginx/modules-enabled, so it works the moment it is installed and nothing has to be added to nginx.conf by hand. Lua and ACME are built for EL9, EL10 and Ubuntu; EL7 gets nginx-module-geoip instead, and njs, Perl, XSLT and image-filter are RPM only.

The same release is on Docker Hub as codeitus/nginx, built on AlmaLinux 9 from these packages and published for amd64 and arm64:

  • the newest image, from whichever pool was released last: docker pull codeitus/nginx
  • the newest Mainline image: docker pull codeitus/nginx:mainline
  • this exact release: docker pull codeitus/nginx:1.31.6

HTTP/3 needs the UDP port published as well as the TCP ones: docker run -d -p 80:80 -p 443:443 -p 443:443/udp codeitus/nginx

Major changes:

  • Change: now the QUIC transport parameters extension received in an SSL connection is always ignored.
  • Bugfix: binary upgrade refused to work if the control API socket was specified and the new nginx executable was built with the ngx_http_perl_module.
  • Bugfix: an error while evaluating a predicate in a predicate location was ignored and the predicate was treated as false.
  • Bugfix: an error during a nested location lookup might be ignored if locations given by regular expressions or predicates were configured at the current level.
  • Bugfix: a segmentation fault might occur while reading configuration if the “geo” directive with the “ranges” parameter was used and the corresponding binary base file was corrupted.

Fixed vulnerabilities:

  • Security: a heap memory buffer overflow might occur in a worker process under certain configurations when using HTTP/3 with OpenSSL 3.5.0 and earlier (CVE-2026-90439).

Security update: NGINX 1.30.5 Stable RPM and DEB packages with HTTP/3, Brotli, TLS 1.3 and OpenSSL 4.0.2 for EL7/EL8/EL9/EL10, Ubuntu 22.04/24.04

nginx 1.30.5 Stable with HTTP/3 support has been added to the CodeIT repository. http2 and ngx_cache_purge are built in, and OpenSSL is linked dynamically against the official OpenSSL 4.0.2 with QUIC support. The Brotli compression module from Google and ngx_http_geoip2 ship as dynamic modules, in nginx-module-brotli and nginx-module-geoip2, which the nginx rpm pulls in automatically (kept as a dependency so that existing installations upgrade without losing those directives; it will be dropped in a few months, and both modules then become truly optional). The packages are built for RHEL, CentOS, AlmaLinux, Rocky Linux and Oracle Linux 7, 8, 9 and 10, and for Ubuntu 22.04 and 24.04.

This update fixes security vulnerabilities. Upgrading is recommended.

More dynamic modules are packaged alongside and are optional: nginx-module-lua with lua-resty-core and lua-resty-lrucache, nginx-module-acme for automatic ACMEv2 certificates, nginx-module-njs, nginx-module-perl, nginx-module-xslt and nginx-module-image-filter. Each one ships its own load_module line in /etc/nginx/modules-enabled, so it works the moment it is installed and nothing has to be added to nginx.conf by hand. Lua and ACME are built for EL9, EL10 and Ubuntu; EL7 gets nginx-module-geoip instead, and njs, Perl, XSLT and image-filter are RPM only.

The same release is on Docker Hub as codeitus/nginx, built on AlmaLinux 9 from these packages and published for amd64 and arm64:

  • the newest image, from whichever pool was released last: docker pull codeitus/nginx
  • the newest Stable image: docker pull codeitus/nginx:stable
  • this exact release: docker pull codeitus/nginx:1.30.5

HTTP/3 needs the UDP port published as well as the TCP ones: docker run -d -p 80:80 -p 443:443 -p 443:443/udp codeitus/nginx

Major changes:

  • Change: now the QUIC transport parameters extension received in an SSL connection is always ignored.

Fixed vulnerabilities:

  • Security: a heap memory buffer overflow might occur in a worker process under certain configurations when using HTTP/3 with OpenSSL 3.5.0 and earlier (CVE-2026-90439).

Security update: mod_http3 v0.0.71 RPM and DEB packages released

mod_http3 v0.0.71 has been added to the CodeIT repository. The packages are built for RHEL, CentOS, AlmaLinux, Rocky Linux and Oracle Linux 7, 8, 9 and 10, and for Ubuntu 22.04 and 24.04.

This update fixes security vulnerabilities. Upgrading is recommended.

Major changes:

  • A host with “h3” in Protocols now serves HTTP/3 with the certificate mod_ssl resolved for it (SSLCertificateFile and mod_md alike), the way mod_http2 rides mod_ssl. H3CertificatePath and H3CertificateKeyPath are removed; drop them from existing configurations.
  • Select the HTTP/3 certificate by SNI, so each virtual host on a shared port serves its own certificate instead of the first host’s.
  • Give every virtual host its own mod_http3 configuration (AP_MODULE_FLAG_ALWAYS_MERGE). A host without H3 directives used to share the main server’s, so per-host settings such as H3AltSvc and H3AltSvcMaxAge were silently ignored and hosts could not carry their own certificate.
  • Test suite: stop.conf now names the same pid file as httpd.conf, so “apachectl -k stop” actually stops the server on httpd builds whose default pid file lives in run/; before, every restart in the suite kept talking to the previous server.

Fixed vulnerabilities:

  • SECURITY: Load the HTTP/3 certificate and key in post_config, while httpd still runs privileged, so a root-only key no longer fails in the unprivileged child and both mod_ssl and mod_http3 read the same files.

Security update: mod_http3 v0.0.70 RPM and DEB packages released

mod_http3 v0.0.70 has been added to the CodeIT repository. The packages are built for RHEL, CentOS, AlmaLinux, Rocky Linux and Oracle Linux 7, 8, 9 and 10, and for Ubuntu 22.04 and 24.04.

This update fixes security vulnerabilities. Upgrading is recommended.

Major changes:

  • Advertised a QPACK dynamic table, sized by H3QpackTableCapacity and H3QpackBlockedStreams, so request headers compress as they do over HTTP/2.
  • Made the request worker pool tunable with H3MinWorkers, H3MaxWorkers and H3MaxWorkerIdleSeconds instead of a fixed 16 to 64 threads.
  • Added H3StreamTimeout, so a client that stops reading can no longer park a request worker until it goes away.
  • Added H3MaxStreamErrors, closing a connection whose client keeps sending malformed requests instead of answering them forever.
  • Published the mod_ssl TLS environment (SSL_PROTOCOL, SSL_CIPHER and friends) for HTTP/3 requests, which mod_ssl does not manage.
  • Added H3SessionTickets, so an operator can control whether returning clients resume instead of running a full handshake.
  • Added H3SocketBufferSize, so the QUIC socket no longer drops datagrams from an undersized OS receive buffer once a connection runs at speed.
  • Enforced H3IdleTimeout in the module event loop, so a connection with no requests is closed instead of being held open by QUIC keepalive pings.
  • Rejected a malformed HTTP/3 request with a stream error instead of closing the connection, so requests in flight beside it survive.
  • Build against httpd 2.4.x as well as trunk; response buckets and the child_stopped hook are now selected at compile time.
  • Detect the stable or devel httpd at configure time and backport the graceful drain to the 2.4.x branch.

Fixed vulnerabilities:

  • SECURITY: Updated the httpd submodule so mpm_event tolerates a connection it never accepted, ending a child crash on an ErrorDocument over HTTP/3.
  • SECURITY: Applied LimitRequestFields and LimitRequestFieldSize to HTTP/3, so a client can no longer grow a stream’s memory with unbounded headers.

NGINX 1.31.5 Mainline RPM and DEB packages with HTTP/3, Brotli, TLS 1.3 and OpenSSL 4.0.2 for EL7/EL8/EL9/EL10, Ubuntu 22.04/24.04

nginx 1.31.5 Mainline with HTTP/3 support has been added to the CodeIT repository. http2 and ngx_cache_purge are built in, and OpenSSL is linked dynamically against the official OpenSSL 4.0.2 with QUIC support. The Brotli compression module from Google and ngx_http_geoip2 ship as dynamic modules, in nginx-module-brotli and nginx-module-geoip2, which the nginx rpm pulls in automatically (kept as a dependency so that existing installations upgrade without losing those directives; it will be dropped in a few months, and both modules then become truly optional). The packages are built for RHEL, CentOS, AlmaLinux, Rocky Linux and Oracle Linux 7, 8, 9 and 10, and for Ubuntu 22.04 and 24.04.

More dynamic modules are packaged alongside and are optional: nginx-module-lua with lua-resty-core and lua-resty-lrucache, nginx-module-acme for automatic ACMEv2 certificates, nginx-module-njs, nginx-module-perl, nginx-module-xslt and nginx-module-image-filter. Each one ships its own load_module line in /etc/nginx/modules-enabled, so it works the moment it is installed and nothing has to be added to nginx.conf by hand. Lua and ACME are built for EL9, EL10 and Ubuntu; EL7 gets nginx-module-geoip instead, and njs, Perl, XSLT and image-filter are RPM only.

The same release is on Docker Hub as codeitus/nginx, built on AlmaLinux 9 from these packages and published for amd64 and arm64:

  • the newest image, from whichever pool was released last: docker pull codeitus/nginx
  • the newest Mainline image: docker pull codeitus/nginx:mainline
  • this exact release: docker pull codeitus/nginx:1.31.5

HTTP/3 needs the UDP port published as well as the TCP ones: docker run -d -p 80:80 -p 443:443 -p 443:443/udp codeitus/nginx

Major changes:

  • Feature: control API.
  • Feature: predicate locations.
  • Feature: the ngx_http_json_module.
  • Feature: the “client_body_early_read” directive.
  • Bugfix: use-after-free might occur in a worker process if proxying with buffering was used and an error occurred while sending the response to an HTTP/2 client.
  • Bugfix: a worker process might not exit or “accept4() failed (9: Bad file descriptor)” alerts might appear in logs if the worker process ran out of file descriptors before graceful shutdown.
  • Bugfix: requests to FastCGI and uwsgi backends were malformed if a parameter name was too long.
  • Bugfixes in HTTP/3, ngx_http_slice_module, and ngx_http_memcached_module.

Security update: openssl 4.0.2 RPM and DEB packages released

openssl 4.0.2 has been added to the CodeIT repository. The packages are built for RHEL, CentOS, AlmaLinux, Rocky Linux and Oracle Linux 7, 8, 9 and 10, and for Ubuntu 22.04 and 24.04.

RedHat FIPS patches removed as per upstream, we now have stock FIPS from OpenSSL to avoid broken web servers.

This update fixes security vulnerabilities. Upgrading is recommended.

Major changes:

  • OpenSSL 4.0.2 is a security patch release. The most severe CVE fixed in this release is Moderate.
  • This release incorporates the following bug fixes and mitigations:
  • Fixed checking of authentication tags for empty ciphertexts for AEAD ciphers in CCM cipher mode.

Fixed vulnerabilities:

  • Fixed QUIC server being able to trigger double free when processing `INITIAL` packet. (CVE-2026-18798)
  • Fixed heap buffer overflow in CMS key unwrapping. (CVE-2026-63072)
  • Fixed invalid pointer dereference in CMP server via crafted `protectionAlg`. (CVE-2026-63076)
  • Fixed unbounded memory growth in QUIC server incoming channel queue. (CVE-2026-14456)
  • Fixed RPK server signature algorithm selection being able to dereference a missing certificate. (CVE-2026-14457)
  • Fixed excessive memory use buffering DTLS records for a future epoch. (CVE-2026-54874)
  • Fixed client-side memory leak in OCSP response checking. (CVE-2026-54876)
  • Fixed untrusted Sender DN being used as a format string in CMP response validation. (CVE-2026-63073)
  • Fixed CMP indefinite cache growth of `extraCerts`. (CVE-2026-63074)
  • Fixed QUIC ACK-only packet retention being able to cause memory exhaustion. (CVE-2026-63075)
  • Fixed possibility of AEAD forgeries with empty ciphertext when using `EVP_Cipher()`. (CVE-2026-75803)

The libraries with QUIC support are still shipped as a separate, non-conflicting openssl-quic-libs package, with its own .so.81.4 suffix, so that they cannot clash with the official .so.X.

NGINX 1.31.4 Mainline RPM and DEB packages with HTTP/3, Brotli, TLS 1.3 and OpenSSL 4.0.1 for EL7/EL8/EL9/EL10, Ubuntu 22.04/24.04

nginx 1.31.4 Mainline with HTTP/3 support has been added to the CodeIT repository. http2 and ngx_cache_purge are built in, and OpenSSL is linked dynamically against the official OpenSSL 4.0.1 with QUIC support. The Brotli compression module from Google and ngx_http_geoip2 ship as dynamic modules, in nginx-module-brotli and nginx-module-geoip2, which the nginx rpm pulls in automatically (kept as a dependency so that existing installations upgrade without losing those directives; it will be dropped in a few months, and both modules then become truly optional). The packages are built for RHEL, CentOS, AlmaLinux, Rocky Linux and Oracle Linux 7, 8, 9 and 10, and for Ubuntu 22.04 and 24.04.

More dynamic modules are packaged alongside and are optional: nginx-module-lua with lua-resty-core and lua-resty-lrucache, nginx-module-acme for automatic ACMEv2 certificates, nginx-module-njs, nginx-module-perl, nginx-module-xslt and nginx-module-image-filter. Each one ships its own load_module line in /etc/nginx/modules-enabled, so it works the moment it is installed and nothing has to be added to nginx.conf by hand. Lua and ACME are built for EL9, EL10 and Ubuntu; EL7 gets nginx-module-geoip instead, and njs, Perl, XSLT and image-filter are RPM only.

The same release is on Docker Hub as codeitus/nginx, built on AlmaLinux 9 from these packages and published for amd64 and arm64:

  • the newest image, from whichever pool was released last: docker pull codeitus/nginx
  • the newest Mainline image: docker pull codeitus/nginx:mainline
  • this exact release: docker pull codeitus/nginx:1.31.4

HTTP/3 needs the UDP port published as well as the TCP ones: docker run -d -p 80:80 -p 443:443 -p 443:443/udp codeitus/nginx

Major changes:

  • Feature: the “proxy_protocol” directive in the stream and mail modules now supports the PROXY protocol version 2.
  • Change: now HTTP/2 and gRPC requests to backends are always sent with the “:authority” pseudo-header, and HTTP/1.1 requests – with the “Host” header.
  • Bugfix: a segmentation fault might occur in a worker process if the “select” method was used.
  • Bugfix: incomplete gRPC responses with a non-zero “Content-Length” header line are now treated as malformed.
  • Bugfix: in binary compatibility with third-party modules using script codes; the bug had appeared in 1.31.3.
  • Bugfix: in the ngx_http_perl_module.
  • Bugfixes in HTTP/2, HTTP/3, ngx_http_image_filter_module, and ngx_http_grpc_module.

Security update: apr-util 1.6.5 RPM and DEB packages released

apr-util 1.6.5 has been added to the CodeIT repository. The packages are built for RHEL, CentOS, AlmaLinux, Rocky Linux and Oracle Linux 7, 8, 9 and 10, and for Ubuntu 22.04 and 24.04.

This update fixes security vulnerabilities. Upgrading is recommended.

Major changes:

  • Fix oracle DBD compilation errors introduced in 1.6.4. PR 70170.
  • apr_brigade: Don’t split the final LF in apr_brigade_split_line() to avoid producing an empty bucket. PR 64273
  • apr_brigade: Metadata buckets are now ignored in apr_brigade_split_line, apr_brigade_flatten and apr_brigade_to_iovec, fixing possible undefined behaviour. PR 68278
  • apr_crypto_openssl: Compatibility with OpenSSL 3.
  • apr_crypto_openssl: use OPENSSL_init_crypto() to initialise OpenSSL on versions 1.1+.
  • apr_memcache: Fix name lookup to allow IPv6 as well as IPv4.
  • configure: Fix Berkeley DB detection with compilers enforcing strict C99 compliance. PR 66396.

Fixed vulnerabilities:

  • SECURITY: CVE-2026-34502: Heap buffer overflow in APR memcached client Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.
  • SECURITY: CVE-2026-34501: Apache Portable Runtime Utility: Heap buffer overflow in APR redis client Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.
  • SECURITY: CVE-2026-34191: Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.
  • SECURITY: CVE-2026-32327: Apache Portable Runtime Utility: apr-util XML stack recursion crash A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
  • SECURITY: CVE-2025-49506: apr_password_validate() vulnerable to timing attack APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.