Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.62 SP5 security update
Red Hat JBoss Core Services is a set of supplementary software for Red Hat JBoss middleware products. This software, such as Apache HTTP Server, is common to multiple JBoss middleware products and packaged under Red Hat JBoss Core Services, to allow for faster distribution of updates and for a more consistent update experience. This release of Red Hat JBoss Core Services Apache HTTP Server 2.4.62 Service Pack 5 serves as a replacement for Red Hat JBoss Core Services Apache HTTP Server 2.4.62 Service Pack 4, and includes bug fixes and enhancements, which are documented in the Release Notes linked to in the References section. Security Fix(es): * jbcs-httpd24-httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516) * jbcs-httpd24-httpd: Apache HTTP Server: Privilege Escalation via .htaccess file manipulation (CVE-2026-24072) * jbcs-httpd24-mod_http2: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service (CVE-2026-48913) * libcurl-1.dll: libcurl: Information disclosure via cached SSL session and early data (CVE-2026-9545) * libcurl-1.dll: libcurl: Security feature bypass due to improper mTLS connection reuse (CVE-2026-8932) * libcurl-1.dll: libcurl: Information disclosure due to failure to clear proxy authentication credentials (CVE-2026-9079) * libcurl-1.dll: libcurl: Information disclosure due to uncleared proxy authentication state (CVE-2026-8927) * libcurl-1.dll: libcurl: Use-after-free vulnerability leading to Denial of Service (CVE-2026-10536) * jbcs-httpd24-httpd: Apache HTTP Server: Arbitrary code execution or denial of service via use-after-free in mod_ldap per-directory configuration (CVE-2026-29167) * jbcs-httpd24-httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue (CVE-2026-42535) * jbcs-httpd24-httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631) * jbcs-httpd24-httpd: SSRF in Apache HTTP Server with mod_proxy loaded (CVE-2024-43204) * curl: curl: Cookie injection via malicious HTTP server using super cookies (CVE-2026-8924) * curl: curl: Information disclosure via incorrect Digest authentication header reuse (CVE-2026-11856) * curl: curl: Insecure connection establishment due to TLS configuration mismatch (CVE-2026-8286) * curl: curl: Man-in-the-middle attack via SSH host key bypass (CVE-2026-9547) * curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect (CVE-2026-3783) * curl: curl: Unauthorized access due to improper HTTP proxy connection reuse (CVE-2026-3784) * curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication (CVE-2026-1965) * curl: libcurl: Unauthorized connection reuse due to a logical error (CVE-2026-8458) * curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse (CVE-2026-5545) * curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP (CVE-2026-12064) * curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse (CVE-2026-7168) * curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies (CVE-2026-6253) * jbcs-httpd24-httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355) * jbcs-httpd24-httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536) * jbcs-httpd24-httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186) * jbcs-httpd24-httpd: Apache HTTP Server - Cross-site scripting in mod_proxy_ftp HTML directory list generation (CVE-2026-29170) * jbcs-httpd24-httpd: jbcs-httpd24-mod_http2: Apache HTTP Server - Out-of-bounds Read in mod_headers and mod_mime with multiple response languages (CVE-2026-43951) * jbcs-httpd24-httpd: Apache HTTP Server - Improper Privilege Management allowing .htaccess authors to read files as httpd user (CVE-2026-44119) * jbcs-httpd24-httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185) * jbcs-httpd24-httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186) * jbcs-httpd24-httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356) A Red Hat Security Bulletin which addresses further details about this flaw is available in the References section. For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
AI Analysis
Technical Summary
The Red Hat Security Advisory RHSA-2026:41906 and RHSA-2026:34109 describe security updates for the Apache HTTP Server (httpd) packages in Red Hat Enterprise Linux 9 and 10. The updates address several vulnerabilities including an incomplete fix for CVE-2023-38709 (now CVE-2024-42516), privilege escalation through .htaccess file manipulation (CVE-2026-24072), timing attacks bypassing digest authentication (CVE-2026-33006), NULL pointer dereference (CVE-2026-29169), heap-based buffer overflows via malicious backend servers and untrusted content (CVE-2026-34356, CVE-2026-42536), buffer over-read via OCSP requests (CVE-2026-44185), denial of service through crafted regular expressions and path handling issues (CVE-2026-44631, CVE-2026-42535), buffer overflow allowing security bypass (CVE-2026-34355), out-of-bounds reads (CVE-2026-43951), and local .htaccess authors reading files with httpd user privileges (CVE-2026-44119). These vulnerabilities impact the Insights proxy container used for routing Red Hat Insights traffic in disconnected or air-gapped environments. The advisory provides updated packages for affected Red Hat Enterprise Linux versions and related components.
Potential Impact
The vulnerabilities collectively allow for privilege escalation, authentication bypass, denial of service, memory corruption (heap-based buffer overflows and buffer over-reads), and unauthorized file access within the Apache HTTP Server environment. This could compromise the confidentiality, integrity, and availability of systems running the affected httpd packages and the Red Hat Insights proxy container. The impact is rated as high by Red Hat Product Security.
Mitigation Recommendations
Red Hat has released updated httpd packages for Red Hat Enterprise Linux 9 and 10 that address these vulnerabilities. Users should apply these official security updates promptly following Red Hat's guidance at https://access.redhat.com/articles/11258. The advisory indicates these fixes are official and should be deployed to remediate the issues. No additional mitigations or workarounds are specified beyond applying the updates.
Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.62 SP5 security update
Description
Red Hat JBoss Core Services is a set of supplementary software for Red Hat JBoss middleware products. This software, such as Apache HTTP Server, is common to multiple JBoss middleware products and packaged under Red Hat JBoss Core Services, to allow for faster distribution of updates and for a more consistent update experience. This release of Red Hat JBoss Core Services Apache HTTP Server 2.4.62 Service Pack 5 serves as a replacement for Red Hat JBoss Core Services Apache HTTP Server 2.4.62 Service Pack 4, and includes bug fixes and enhancements, which are documented in the Release Notes linked to in the References section. Security Fix(es): * jbcs-httpd24-httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516) * jbcs-httpd24-httpd: Apache HTTP Server: Privilege Escalation via .htaccess file manipulation (CVE-2026-24072) * jbcs-httpd24-mod_http2: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service (CVE-2026-48913) * libcurl-1.dll: libcurl: Information disclosure via cached SSL session and early data (CVE-2026-9545) * libcurl-1.dll: libcurl: Security feature bypass due to improper mTLS connection reuse (CVE-2026-8932) * libcurl-1.dll: libcurl: Information disclosure due to failure to clear proxy authentication credentials (CVE-2026-9079) * libcurl-1.dll: libcurl: Information disclosure due to uncleared proxy authentication state (CVE-2026-8927) * libcurl-1.dll: libcurl: Use-after-free vulnerability leading to Denial of Service (CVE-2026-10536) * jbcs-httpd24-httpd: Apache HTTP Server: Arbitrary code execution or denial of service via use-after-free in mod_ldap per-directory configuration (CVE-2026-29167) * jbcs-httpd24-httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue (CVE-2026-42535) * jbcs-httpd24-httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631) * jbcs-httpd24-httpd: SSRF in Apache HTTP Server with mod_proxy loaded (CVE-2024-43204) * curl: curl: Cookie injection via malicious HTTP server using super cookies (CVE-2026-8924) * curl: curl: Information disclosure via incorrect Digest authentication header reuse (CVE-2026-11856) * curl: curl: Insecure connection establishment due to TLS configuration mismatch (CVE-2026-8286) * curl: curl: Man-in-the-middle attack via SSH host key bypass (CVE-2026-9547) * curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect (CVE-2026-3783) * curl: curl: Unauthorized access due to improper HTTP proxy connection reuse (CVE-2026-3784) * curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication (CVE-2026-1965) * curl: libcurl: Unauthorized connection reuse due to a logical error (CVE-2026-8458) * curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse (CVE-2026-5545) * curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP (CVE-2026-12064) * curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse (CVE-2026-7168) * curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies (CVE-2026-6253) * jbcs-httpd24-httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355) * jbcs-httpd24-httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536) * jbcs-httpd24-httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186) * jbcs-httpd24-httpd: Apache HTTP Server - Cross-site scripting in mod_proxy_ftp HTML directory list generation (CVE-2026-29170) * jbcs-httpd24-httpd: jbcs-httpd24-mod_http2: Apache HTTP Server - Out-of-bounds Read in mod_headers and mod_mime with multiple response languages (CVE-2026-43951) * jbcs-httpd24-httpd: Apache HTTP Server - Improper Privilege Management allowing .htaccess authors to read files as httpd user (CVE-2026-44119) * jbcs-httpd24-httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185) * jbcs-httpd24-httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186) * jbcs-httpd24-httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356) A Red Hat Security Bulletin which addresses further details about this flaw is available in the References section. For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Red Hat Security Advisory RHSA-2026:41906 and RHSA-2026:34109 describe security updates for the Apache HTTP Server (httpd) packages in Red Hat Enterprise Linux 9 and 10. The updates address several vulnerabilities including an incomplete fix for CVE-2023-38709 (now CVE-2024-42516), privilege escalation through .htaccess file manipulation (CVE-2026-24072), timing attacks bypassing digest authentication (CVE-2026-33006), NULL pointer dereference (CVE-2026-29169), heap-based buffer overflows via malicious backend servers and untrusted content (CVE-2026-34356, CVE-2026-42536), buffer over-read via OCSP requests (CVE-2026-44185), denial of service through crafted regular expressions and path handling issues (CVE-2026-44631, CVE-2026-42535), buffer overflow allowing security bypass (CVE-2026-34355), out-of-bounds reads (CVE-2026-43951), and local .htaccess authors reading files with httpd user privileges (CVE-2026-44119). These vulnerabilities impact the Insights proxy container used for routing Red Hat Insights traffic in disconnected or air-gapped environments. The advisory provides updated packages for affected Red Hat Enterprise Linux versions and related components.
Potential Impact
The vulnerabilities collectively allow for privilege escalation, authentication bypass, denial of service, memory corruption (heap-based buffer overflows and buffer over-reads), and unauthorized file access within the Apache HTTP Server environment. This could compromise the confidentiality, integrity, and availability of systems running the affected httpd packages and the Red Hat Insights proxy container. The impact is rated as high by Red Hat Product Security.
Mitigation Recommendations
Red Hat has released updated httpd packages for Red Hat Enterprise Linux 9 and 10 that address these vulnerabilities. Users should apply these official security updates promptly following Red Hat's guidance at https://access.redhat.com/articles/11258. The advisory indicates these fixes are official and should be deployed to remediate the issues. No additional mitigations or workarounds are specified beyond applying the updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:34109
- Cve Count
- 13
- Additional Cves
- ["CVE-2026-24072","CVE-2026-29169","CVE-2026-33006","CVE-2026-34355","CVE-2026-34356","CVE-2026-42535","CVE-2026-42536","CVE-2026-43951","CVE-2026-44119","CVE-2026-44185","CVE-2026-44186","CVE-2026-44631"]
- Cvss Version
- null
Threat ID: 6a4e4ec5c9d9e3dbe3286fcc
Added to database: 07/08/2026, 13:21:09 UTC
Last enriched: 08/16/2026, 16:57:37 UTC
Last updated: 09/02/2026, 17:02:36 UTC
Views: 69
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.