Red Hat Product Errata RHSA-2026:36373 - Security Advisory Issued: 2026-07-07 Updated: 2026-07-07 RHSA-2026:36373 - Security Advisory Overview Updated Packages Synopsis Important: httpd:2.4 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the httpd:2.4 module is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server. Security Fix(es): httpd: Apache HTTP Server: HTTP/2 DoS by Memory Increase (CVE-2025-53020) httpd: mod_proxy_ajp: heap-based buffer over-read and memory disclosure in ajp_parse_data() (CVE-2026-34059) httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check (CVE-2026-34032) httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions (CVE-2026-33857) httpd: mod_authn_socache: NULL pointer dereference can cause a child process crash (CVE-2026-33007) Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow (CVE-2026-28780) httpd: HTTP/2: Remote Denial of Service via compression bomb and Slowloris-style attack (CVE-2026-49975) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 x86_64 Red Hat Enterprise Linux Server - TUS 8.8 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64 Fixes BZ - 2379343 - CVE-2025-53020 mod_http2: Apache HTTP Server: HTTP/2 DoS by Memory Increase BZ - 2464940 - CVE-2026-34059 httpd: mod_proxy_ajp: heap-based buffer over-read and memory disclosure in ajp_parse_data() BZ - 2464952 - CVE-2026-34032 httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check BZ - 2464953 - CVE-2026-33857 httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions BZ - 2465299 - CVE-2026-33007 httpd: mod_authn_socache: NULL pointer dereference can cause a child process crash BZ - 2466913 - CVE-2026-28780 Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow BZ - 2485371 - CVE-2026-49975 httpd: HTTP/2: Remote Denial of Service via compression bomb and Slowloris-style attack CVEs CVE-2025-53020 CVE-2026-28780 CVE-2026-33007 CVE-2026-33857 CVE-2026-34032 CVE-2026-34059 CVE-2026-49975 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 SRPM httpd-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.src.rpm SHA-256: ed68b4e71d0160c7346a77b040929a0a29b8f84fbb4c5925538256c0a862a874 mod_http2-1.15.7-8.module+el8.8.0+24497+e470c0e2.7.src.rpm SHA-256: f7befe204c54b489775f36a2389a08fff4d1c7ddade04ff6d0e58991b4cfaa03 mod_md-2.0.8-8.module+el8.8.0+23840+d7e7db80.1.src.rpm SHA-256: 5a8f03968d4fa68964fa338bd665a370cd73c4a0ec0fa98d35a2297801443c52 x86_64 httpd-filesystem-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.noarch.rpm SHA-256: 00b01b8bea92303b0c356b14ef861268e06e39340496cf78f2e6d1abdeecbb71 httpd-manual-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.noarch.rpm SHA-256: 49d7ec45f4d03d4b460030bbe08eeffc76773c081e8bcab0b029a03ba2aef7b5 httpd-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.x86_64.rpm SHA-256: cc89c008ac326fc79e63ba4f632c199cc6229be34d46b3bfd6a1bb1e5339cb1c httpd-debuginfo-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.x86_64.rpm SHA-256: 3b9db4229a8f0c61fd15ed3ea22d4b36f2621d5c29c9f89942b8b7998e36f0a3 httpd-debugsource-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.x86_64.rpm SHA-256: 9e1110631e1bafbcb1bcff24d702c89abe09b97ff989b3762932125ee026ddf7 httpd-devel-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.x86_64.rpm SHA-256: 96fa597aeea7112b77419cf4a18f44f6eaa8f258b19dcd8b2912328f74bc186c httpd-filesystem-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.noarch.rpm SHA-256: 00b01b8bea92303b0c356b14ef861268e06e39340496cf78f2e6d1abdeecbb71 httpd-manual-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.noarch.rpm SHA-256: 49d7ec45f4d03d4b460030bbe08eeffc76773c081e8bcab0b029a03ba2aef7b5 httpd-tools-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.x86_64.rpm SHA-256: 40719e50dfa1e77eaa2e31176b5cabeb05793c0a10c064e4febd71b5ff608b55 httpd-tools-debuginfo-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.x86_64.rpm SHA-256: 6ac728a77ce68955ac88687e6311a74484f38f089caccf7c409ea14ae1bc7023 mod_http2-1.15.7-8.module+el8.8.0+24497+e470c0e2.7.x86_64.rpm SHA-256: 03c9a2d9cea60835af45fe7b93a1ab3f240b913d3bff1df83c3b21823ff7510e mod_http2-debuginfo-1.15.7-8.module+el8.8.0+24497+e470c0e2.7.x86_64.rpm SHA-256: 7463c5c3628f6264b44f7b61125001ffe615e6709db900c09c821928b237ebbf mod_http2-debugsource-1.15.7-8.module+el8.8.0+24497+e470c0e2.7.x86_64.rpm SHA-256: f4fabab928bed8722911ecbf07cd836b3311528476d2c25667b4705f65e54d3d mod_ldap-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.x86_64.rpm SHA-256: bc5bd811e05aa700b390d9cd8dde881be5dc865252ca02b54a815d87c7fc8bfa mod_ldap-debuginfo-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.x86_64.rpm SHA-256: 4325786fced0797a2b96b12ad1aeff12a82830cc9fbf030b86802745f2d8ab6a mod_md-2.0.8-8.module+el8.8.0+23840+d7e7db80.1.x86_64.rpm SHA-256: 5e170ab5ae0d73cb482984d655e46639e4b6036a27f25f61fdfddea20b62ceea mod_md-debuginfo-2.0.8-8.module+el8.8.0+23840+d7e7db80.1.x86_64.rpm SHA-256: 5486ced50671b6b95aa42ce67d3ef76613d89b6edda81bdb4cfcb60851095a5e mod_md-debugsource-2.0.8-8.module+el8.8.0+23840+d7e7db80.1.x86_64.rpm SHA-256: 5b7ef1518dc6a791dc8372736ee9f11280d178ff3ddc15f194aaa46c01d8b4b1 mod_proxy_html-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.x86_64.rpm SHA-256: 6cb2764e3fad1d47b18d665163736dd34f7a0e797b90014038ceaaf6568ba29d mod_proxy_html-debuginfo-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.x86_64.rpm SHA-256: b6e432dcfd5421c87454041e9b718845c77ba276bae02e61b6712381ef1d543d mod_session-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.x86_64.rpm SHA-256: a079b238d9b2e74ee9a602975371b90a365ccd0fd3e97d80cea8eeb01f7c6182 mod_session-debuginfo-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.x86_64.rpm SHA-256: 4c1bff01962712bd05a222b0f92318b88a1a4a8ff12ed6326ba51d215d15bd2e mod_ssl-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.x86_64.rpm SHA-256: 9d1e777d09457224cd9aa0b1fcdf04e998ec14bf93fa67421f3387b3d9ecf862 mod_ssl-debuginfo-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.x86_64.rpm SHA-256: 7879daa599e612a7865410a52f951c3fdcb26e5bcf9ea40ef1a3c0d4567ae903 Red Hat Enterprise Linux Server - TUS 8.8 SRPM httpd-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.src.rpm SHA-256: ed68b4e71d0160c7346a77b040929a0a29b8f84fbb4c5925538256c0a862a874 mod_http2-1.15.7-8.module+el8.8.0+24497+e470c0e2.7.src.rpm SHA-256: f7befe204c54b489775f36a2389a08fff4d1c7ddade04ff6d0e58991b4cfaa03 mod_md-2.0.8-8.module+el8.8.0+23840+d7e7db80.1.src.rpm SHA-256: 5a8f03968d4fa68964fa338bd665a370cd73c4a0ec0fa98d35a2297801443c52 x86_64 httpd-filesystem-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.noarch.rpm SHA-256: 00b01b8bea92303b0c356b14ef861268e06e39340496cf78f2e6d1abdeecbb71 httpd-manual-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.noarch.rpm SHA-256: 49d7ec45f4d03d4b460030bbe08eeffc76773c081e8bcab0b029a03ba2aef7b5 httpd-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.x86_64.rpm SHA-256: cc89c008ac326fc79e63ba4f632c199cc6229be34d46b3bfd6a1bb1e5339cb1c httpd-debuginfo-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.x86_64.rpm SHA-256: 3b9db4229a8f0c61fd15ed3ea22d4b36f2621d5c29c9f89942b8b7998e36f0a3 httpd-debugsource-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.x86_64.rpm SHA-256: 9e1110631e1bafbcb1bcff24d702c89abe09b97ff989b3762932125ee026ddf7 httpd-devel-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.x86_64.rpm SHA-256: 96fa597aeea7112b77419cf4a18f44f6eaa8f258b19dcd8b2912328f74bc186c httpd-filesystem-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.noarch.rpm SHA-256: 00b01b8bea92303b0c356b14ef861268e06e39340496cf78f2e6d1abdeecbb71 httpd-manual-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.noarch.rpm SHA-256: 49d7ec45f4d03d4b460030bbe08eeffc76773c081e8bcab0b029a03ba2aef7b5 httpd-tools-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.x86_64.rpm SHA-256: 40719e50dfa1e77eaa2e31176b5cabeb05793c0a10c064e4febd71b5ff608b55 httpd-tools-debuginfo-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.x86_64.rpm SHA-256: 6ac728a77ce68955ac88687e6311a74484f38f089caccf7c409ea14ae1bc7023 mod_http2-1.15.7-8.module+el8.8.0+24497+e470c0e2.7.x86_64.rpm SHA-256: 03c9a2d9cea60835af45fe7b93a1ab3f240b913d3bff1df83c3b21823ff7510e mod_http2-debuginfo-1.15.7-8.module+el8.8.0+24497+e470c0e2.7.x86_64.rpm SHA-256: 7463c5c3628f6264b44f7b61125001ffe615e6709db900c09c821928b237ebbf mod_http2-debugsource-1.15.7-8.module+el8.8.0+24497+e470c0e2.7.x86_64.rpm SHA-256: f4fabab928bed8722911ecbf07cd836b3311528476d2c25667b4705f65e54d3d mod_ldap-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.x86_64.rpm SHA-256: bc5bd811e05aa700b390d9cd8dde881be5dc865252ca02b54a815d87c7fc8bfa mod_ldap-debuginfo-2.4.37-56.module+el8.8.0+24497+e470c0e2.12.x86_64.rpm SHA-256: 4325786fced0797a2b96b12ad1aeff12a82830cc9fbf030b86802745f2d8ab6a mod_md-2.0.8-8.module+el8.8
This Red Hat security update addresses multiple vulnerabilities in the Apache HTTP Server (`httpd:2.4` module), including high-severity issues such as HTTP/2 denial-of-service via memory exhaustion (CVE-2025-53020, CVSS 7.5) and several heap-based buffer over-reads and potential code execution flaws in the `mod_proxy_ajp` module. Based on authoritative NVD data, affected versions include Apache HTTP Server 2.4.17 through 2.4.63 for CVE-2025-53020 and versions prior to 2.4.67 for CVE-2026-34059 and CVE-2026-34032. The fix requires updating the `httpd` packages to the patched version provided by Red Hat for the specified Enterprise Linux channels.