rpm package
almalinux/httpd
pkg:rpm/almalinux/httpd
Vulnerabilities (66)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-65082 | Med | 6.5 | < 2.4.37-65.module_el8.10.0+4088+57f011c1.7 | 2.4.37-65.module_el8.10.0+4088+57f011c1.7 | Dec 5, 2025 | Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server fr | |
| CVE-2025-55753 | Hig | 7.5 | < 2.4.37-65.module_el8.10.0+4088+57f011c1.7 | 2.4.37-65.module_el8.10.0+4088+57f011c1.7 | Dec 5, 2025 | An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Ap | |
| CVE-2025-53020 | Hig | 7.5 | < 2.4.37-65.module_el8.10.0+4185+0955a0d7.8 | 2.4.37-65.module_el8.10.0+4185+0955a0d7.8 | Jul 10, 2025 | Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue. | |
| CVE-2025-49812 | Hig | 7.4 | < 2.4.62-4.el9_6.4 | 2.4.62-4.el9_6.4 | Jul 10, 2025 | In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upgrades are affected. | |
| CVE-2025-49630 | Hig | 7.5 | < 2.4.37-65.module_el8.10.0+4044+ea5f78b1.5 | 2.4.37-65.module_el8.10.0+4044+ea5f78b1.5 | Jul 10, 2025 | In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend | |
| CVE-2025-23048 | Cri | 9.1 | < 2.4.62-4.el9_6.4 | 2.4.62-4.el9_6.4 | Jul 10, 2025 | In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected when mod_ssl is configured for multiple virtual hosts, with each restricted to a d | |
| CVE-2024-47252 | Hig | 7.5 | < 2.4.62-4.el9_6.4 | 2.4.62-4.el9_6.4 | Jul 10, 2025 | Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where CustomLog is used with "%{varname}x" or "%{varna | |
| CVE-2024-42516 | Hig | 7.5 | < 2.4.63-13.el10_2.4 | 2.4.63-13.el10_2.4 | Jul 10, 2025 | HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 but the patch include | |
| CVE-2024-39573 | Hig | 7.5 | < 2.4.37-65.module_el8.10.0+3872+9b8ab21e.1 | 2.4.37-65.module_el8.10.0+3872+9b8ab21e.1 | Jul 1, 2024 | Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users are recommended to upgrade to version 2.4.60, which fixes this issue. | |
| CVE-2024-38477 | Hig | 7.5 | < 2.4.37-65.module_el8.10.0+3872+9b8ab21e.1 | 2.4.37-65.module_el8.10.0+3872+9b8ab21e.1 | Jul 1, 2024 | null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are recommended to upgrade to version 2.4.60, which fixes this issue. | |
| CVE-2024-38476 | Cri | 9.8 | < 2.4.57-11.el9_4.1 | 2.4.57-11.el9_4.1 | Jul 1, 2024 | Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes t | |
| CVE-2024-38475 | Cri | 9.1 | KEV | < 2.4.37-65.module_el8.10.0+3872+9b8ab21e.1 | 2.4.37-65.module_el8.10.0+3872+9b8ab21e.1 | Jul 1, 2024 | Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source |
| CVE-2024-38474 | Cri | 9.8 | < 2.4.37-65.module_el8.10.0+3872+9b8ab21e.1 | 2.4.37-65.module_el8.10.0+3872+9b8ab21e.1 | Jul 1, 2024 | Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users a | |
| CVE-2024-38473 | Hig | 8.1 | < 2.4.37-65.module_el8.10.0+3872+9b8ab21e.1 | 2.4.37-65.module_el8.10.0+3872+9b8ab21e.1 | Jul 1, 2024 | Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, which fixes this issue | |
| CVE-2024-27316 | Hig | 7.5 | < 2.4.37-62.module_el8.9.0+3646+acd210d0 | 2.4.37-62.module_el8.9.0+3646+acd210d0 | Apr 4, 2024 | HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion. | |
| CVE-2024-24795 | Med | 6.3 | < 2.4.62-1.el9 | 2.4.62-1.el9 | Apr 4, 2024 | HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue. | |
| CVE-2023-38709 | Hig | 7.3 | < 2.4.37-65.module_el8.10.0+3860+a6e26e50 | 2.4.37-65.module_el8.10.0+3860+a6e26e50 | Apr 4, 2024 | Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58. | |
| CVE-2023-45802 | Med | 5.9 | < 2.4.37-64.module_el8.10.0+3761+75f8c656 | 2.4.37-64.module_el8.10.0+3761+75f8c656 | Oct 23, 2023 | When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were not reclaimed immediately. Instead, de-allocation was deferred to connection close. A client could send new requests and resets, keeping the connection busy an | |
| CVE-2023-31122 | Hig | 7.5 | < 2.4.57-8.el9 | 2.4.57-8.el9 | Oct 23, 2023 | Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57. | |
| CVE-2023-44487 | Hig | 7.5 | KEV | < 2.4.37-64.module_el8.10.0+3761+75f8c656 | 2.4.37-64.module_el8.10.0+3761+75f8c656 | Oct 10, 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
- affected < 2.4.37-65.module_el8.10.0+4088+57f011c1.7fixed 2.4.37-65.module_el8.10.0+4088+57f011c1.7
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server fr
- affected < 2.4.37-65.module_el8.10.0+4088+57f011c1.7fixed 2.4.37-65.module_el8.10.0+4088+57f011c1.7
An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Ap
- affected < 2.4.37-65.module_el8.10.0+4185+0955a0d7.8fixed 2.4.37-65.module_el8.10.0+4185+0955a0d7.8
Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.
- affected < 2.4.62-4.el9_6.4fixed 2.4.62-4.el9_6.4
In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upgrades are affected.
- affected < 2.4.37-65.module_el8.10.0+4044+ea5f78b1.5fixed 2.4.37-65.module_el8.10.0+4044+ea5f78b1.5
In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend
- affected < 2.4.62-4.el9_6.4fixed 2.4.62-4.el9_6.4
In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected when mod_ssl is configured for multiple virtual hosts, with each restricted to a d
- affected < 2.4.62-4.el9_6.4fixed 2.4.62-4.el9_6.4
Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where CustomLog is used with "%{varname}x" or "%{varna
- affected < 2.4.63-13.el10_2.4fixed 2.4.63-13.el10_2.4
HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 but the patch include
- affected < 2.4.37-65.module_el8.10.0+3872+9b8ab21e.1fixed 2.4.37-65.module_el8.10.0+3872+9b8ab21e.1
Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
- affected < 2.4.37-65.module_el8.10.0+3872+9b8ab21e.1fixed 2.4.37-65.module_el8.10.0+3872+9b8ab21e.1
null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
- affected < 2.4.57-11.el9_4.1fixed 2.4.57-11.el9_4.1
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes t
- affected < 2.4.37-65.module_el8.10.0+3872+9b8ab21e.1fixed 2.4.37-65.module_el8.10.0+3872+9b8ab21e.1
Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source
- affected < 2.4.37-65.module_el8.10.0+3872+9b8ab21e.1fixed 2.4.37-65.module_el8.10.0+3872+9b8ab21e.1
Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users a
- affected < 2.4.37-65.module_el8.10.0+3872+9b8ab21e.1fixed 2.4.37-65.module_el8.10.0+3872+9b8ab21e.1
Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, which fixes this issue
- affected < 2.4.37-62.module_el8.9.0+3646+acd210d0fixed 2.4.37-62.module_el8.9.0+3646+acd210d0
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
- affected < 2.4.62-1.el9fixed 2.4.62-1.el9
HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.
- affected < 2.4.37-65.module_el8.10.0+3860+a6e26e50fixed 2.4.37-65.module_el8.10.0+3860+a6e26e50
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.
- affected < 2.4.37-64.module_el8.10.0+3761+75f8c656fixed 2.4.37-64.module_el8.10.0+3761+75f8c656
When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were not reclaimed immediately. Instead, de-allocation was deferred to connection close. A client could send new requests and resets, keeping the connection busy an
- affected < 2.4.57-8.el9fixed 2.4.57-8.el9
Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.
- affected < 2.4.37-64.module_el8.10.0+3761+75f8c656fixed 2.4.37-64.module_el8.10.0+3761+75f8c656
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Page 2 of 4