Back to Security Advisories
High 2026-07-21

Httpd Security Update — AlmaLinux 9 (ALSA-2026:41906)

AlmaLinux 9

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server. Security Fix(es): * httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516) * Apache HTTP Server: mod_rewrite: Apache HTTP Server: Privilege Escalation via .htaccess file manipulation (CVE-2026-24072) *…

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

* httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516)
* Apache HTTP Server: mod_rewrite: Apache HTTP Server: Privilege Escalation via .htaccess file manipulation (CVE-2026-24072)
*…

Type:
security

Severity:
important

Release date:
2026-07-21

Description:
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

* httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516)
* Apache HTTP Server: mod_rewrite: Apache HTTP Server: Privilege Escalation via .htaccess file manipulation (CVE-2026-24072)
* httpd: mod_auth_digest: timing attack allows a bypass of digest authentication (CVE-2026-33006)
* httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169)
* httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356)
* httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
* httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631)
* httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186)
* httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue (CVE-2026-42535)
* httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536)
* httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355)
* httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime (CVE-2026-43951)
* httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges (CVE-2026-44119)

Bug Fix(es) and Enhancement(s):

* address Moderate severity issues from httpd 2.4.68 [almalinux-9.8.z] (JIRA:AlmaLinux-184520)
* mod_proxy_html regression in CVE-2026-34355 fix [almalinux-9.8.z] (JIRA:AlmaLinux-192752)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Updated packages listed below:

Architecture Package Checksum
aarch64 mod_lua-2.4.62-13.el9_8.5.aarch64.rpm 08bb578ed654bfe1ca8b80584d4738b9327fe04edfe94d2468abd376d6661e3e
aarch64 mod_proxy_html-2.4.62-13.el9_8.5.aarch64.rpm 4705bc91cac9a4f12a820aa7ab7fd191672899efbb78a5d205b0a6203ab16f6f
aarch64 httpd-devel-2.4.62-13.el9_8.5.aarch64.rpm 90eaf6a19e2b9365f169673e73cf4b3c578015ac433ce5f6f1d223a840968537
aarch64 httpd-tools-2.4.62-13.el9_8.5.aarch64.rpm 985e785b9569976c2bf369c1d063d801641f7a7a3b4f7155dca00d1fb2f7389d
aarch64 mod_session-2.4.62-13.el9_8.5.aarch64.rpm 99500a2eea8ab006af701e92b8cb53b503ae69c906ab9afa5eab07dd2996e07c
aarch64 mod_ssl-2.4.62-13.el9_8.5.aarch64.rpm c656cf599ff919ab2eab3c5c7ec2b71441c3e35ebd5568a0da53c9c70ddb317a
aarch64 mod_ldap-2.4.62-13.el9_8.5.aarch64.rpm ce922d976707b05a987e44083d9effa729721546aa1c75dfc10639cf517cc847
aarch64 httpd-2.4.62-13.el9_8.5.aarch64.rpm d3465243dfbd806646c8b879e13ff36a99121d4ee025e885fd2fe54c636a53b7
aarch64 httpd-core-2.4.62-13.el9_8.5.aarch64.rpm d5bddd69f887638b3a9f6343d1678b7d2afb7fd6751f3cf9e84ff7294850d2ae
noarch httpd-filesystem-2.4.62-13.el9_8.5.noarch.rpm 4c04f408e6394dcbe2bb7ccca5cb12834258a843eac44ff7fe5558f6fa073d18
noarch httpd-manual-2.4.62-13.el9_8.5.noarch.rpm f385fb8cd4918d9180d8f574c70c9f3d6c7e1ab572c7bbfdc488706f96497b4d
ppc64le httpd-2.4.62-13.el9_8.5.ppc64le.rpm 265ef1e8751ed989622d87095e3d7cae73de4f8b02f49d15aeb10c95dbe998de
ppc64le mod_lua-2.4.62-13.el9_8.5.ppc64le.rpm 316c11c76ee432cb639aad7d33878a5f432b1d9882627d8b246d79c87cf00a87
ppc64le mod_session-2.4.62-13.el9_8.5.ppc64le.rpm 4642b851312c1665c86a44ca061845b529fb72e6915d4b186f638e88c3e3e762
ppc64le mod_ldap-2.4.62-13.el9_8.5.ppc64le.rpm 8160b3f32e5e56743c88a963d647cfecbb688831033040612d4df525241e21bd
ppc64le httpd-tools-2.4.62-13.el9_8.5.ppc64le.rpm 86b18596916a907d249e88f944b3ef9c6b6c592405942e13c6d27ffd07418ac0
ppc64le httpd-devel-2.4.62-13.el9_8.5.ppc64le.rpm 97da60394112810d5382a0e49b7a321d58132f2c8a193d9453c54ee2e905e8bf
ppc64le mod_proxy_html-2.4.62-13.el9_8.5.ppc64le.rpm b73a54ff6b529afde031f2b5f256f931095334ef6c143bbfd59c0681ecc44e25
ppc64le httpd-core-2.4.62-13.el9_8.5.ppc64le.rpm bfef30bafd5f3cac8c22f981ce08f0a6c42d41e5b003d4d95a1f1ee900db3a62
ppc64le mod_ssl-2.4.62-13.el9_8.5.ppc64le.rpm d5075118476c4a3726ab90e1060cc582e126e24c981810e760e01f009e97cdff
s390x mod_ldap-2.4.62-13.el9_8.5.s390x.rpm 2a89752ba8af44e64c71cfc326609d5f918e59ca93db966cd25494159d5e0ea7
s390x httpd-core-2.4.62-13.el9_8.5.s390x.rpm 40469b8c0c84ed1464cc25af8ebb919851d1c1edb61a17595e1ab876916836fb
s390x mod_session-2.4.62-13.el9_8.5.s390x.rpm 41e9b493080909a7b8ce51f3acf65712394cf0d195a6da7d29ca4c270a974217
s390x mod_ssl-2.4.62-13.el9_8.5.s390x.rpm 5249252b31165c91eed6dd2d94762535833e01ccfd5653ee74b876eace194296
s390x mod_proxy_html-2.4.62-13.el9_8.5.s390x.rpm 7bd6ebd818d3c5d3aa595b004a90dcc0e0345379ef78ff1b8c3225336efa2b2a
s390x httpd-2.4.62-13.el9_8.5.s390x.rpm 80a3247074b63e8cc96c9b4f02f4a2e44d0e449948f6bb93881dcb4d41a19788
s390x mod_lua-2.4.62-13.el9_8.5.s390x.rpm a1918420691119691f8ff56109b709479858a2839a170ee138d41438c50fd879
s390x httpd-devel-2.4.62-13.el9_8.5.s390x.rpm e1f42810c65626782211fb4cf523ada034bb1dbd087357b21fd74782528d4694
s390x httpd-tools-2.4.62-13.el9_8.5.s390x.rpm ef411c1d2e4c7e06ca5d04113908ef09f9de06cc50226f6e7fbd1fad568f9ddd
x86_64 httpd-core-2.4.62-13.el9_8.5.x86_64.rpm 0db229d8f6c095b8fbef70d77be5f5d1a7c0fc4f523b152fc8a9d0a4467f83e4
x86_64 httpd-2.4.62-13.el9_8.5.x86_64.rpm 18b9df4549235555a664b8543c8ae0bc4068cc22d1f72dfcb29b66925efe9de1
x86_64 mod_ssl-2.4.62-13.el9_8.5.x86_64.rpm 51b51b6ed3b128f1b0b538d6e27ca301a518129ade87cf06ddd5b7ad1613a39c
x86_64 httpd-devel-2.4.62-13.el9_8.5.x86_64.rpm 8e6ef0ab752affb6d35fa42f51206e80157ec4a17887054ba8fea4ac61c30271
x86_64 mod_lua-2.4.62-13.el9_8.5.x86_64.rpm 93136207de7e6ea0ef96c6981fddbdeb9edb248f038d6d4698ab73d3f8c9fe96
x86_64 httpd-tools-2.4.62-13.el9_8.5.x86_64.rpm 943bf6bb663bb976977576b343b3c15df1fce0cf138ba0768d0236adff806956
x86_64 mod_proxy_html-2.4.62-13.el9_8.5.x86_64.rpm b7b4e69403bdb27f705d693d55be4e8a9180966c07d1420ba207cdb50ccc0cf9
x86_64 mod_ldap-2.4.62-13.el9_8.5.x86_64.rpm c3333a819ca905a716ba0a985894acfb697ac749492b0b77326ac9ef0a27e0b4
x86_64 mod_session-2.4.62-13.el9_8.5.x86_64.rpm cee06c5b8b37b3fae4b54ea01132989b67d921cd0e3c9449c7fa8f50d70b553c

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System