-
Wed Jul 01 2026 EL Errata <el-errata_ww@oracle.com> - 2.4.63-13.0.1.el10_2.4
- Replace index.html with Oracle's index page oracle_index.html.
-
Tue Jun 23 2026 Luboš Uhliarik <luhliari@redhat.com> - 2.4.63-13.4
- Resolves: RHEL-186221 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
via malicious backend servers (CVE-2026-34356)
- Resolves: RHEL-186195 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
via untrusted content in mod_xml2enc (CVE-2026-42536)
- Resolves: RHEL-186182 - httpd: Apache HTTP Server: Buffer overflow in
mod_proxy_html allows security bypass (CVE-2026-34355)
- Resolves: RHEL-186158 - httpd: Apache HTTP Server: Buffer Over-read via
outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
- Resolves: RHEL-184305 - httpd: Apache HTTP Server: Denial of Service via
crafted regular expressions (CVE-2026-44631)
- Resolves : RHEL-182581 - httpd: incomplete fix for
CVE-2023-38709 (CVE-2024-42516)
- Resolves: RHEL-175621 - httpd: NULL pointer dereference via specially crafted
request (CVE-2026-29169)
- Also addresses CVE-2026-44119, CVE-2026-44186, CVE-2026-42535,
CVE-2026-24072, CVE-2026-33006, CVE-2026-43951
-
Mon May 11 2026 Luboš Uhliarik <luhliari@redhat.com> - 2.4.63-13.1
- Resolves: RHEL-173549 - httpd: Apache HTTP Server mod_proxy_ajp: Arbitrary
code execution via heap-based buffer overflow (CVE-2026-28780)
- Resolves: RHEL-175065 - httpd: NULL pointer dereference can cause a child
process crash (CVE-2026-33007)
- Resolves: RHEL-175095 - httpd: off-by-one out-of-bounds reads in AJP getter
functions (CVE-2026-33857)
- Resolves: RHEL-175039 - httpd: heap-based buffer over-read due to missing
null-termination check (CVE-2026-34032)
- Resolves: RHEL-175050 - httpd: heap-based buffer over-read and memory
disclosure in ajp_parse_data() (CVE-2026-34059)
-
Thu Feb 12 2026 Luboš Uhliarik <luhliari@redhat.com> - 2.4.63-13
- Resolves: RHEL-145713 - [RFE] Need miliseconds time stamp in ErrorLogFormat
-
Fri Jan 02 2026 Luboš Uhliarik <luhliari@redhat.com> - 2.4.63-12
- Resolves: RHEL-135053 - httpd: Apache HTTP Server: mod_userdir+suexec bypass
via AllowOverride FileInfo (CVE-2025-66200)
- Resolves: RHEL-135036 - httpd: Apache HTTP Server: CGI environment variable
override (CVE-2025-65082)
- Resolves: RHEL-134468 - httpd: Apache HTTP Server: Server Side Includes adds
query string to #exec cmd=... (CVE-2025-58098)
-
Thu Dec 18 2025 Luboš Uhliarik <luhliari@redhat.com> - 2.4.63-11
- Resolves: RHEL-131829 - Fix error page messaging when error handling fails
-
Thu Nov 06 2025 Luboš Uhliarik <luhliari@redhat.com> - 2.4.63-10
- Resolves: RHEL-125880 - mod_ssl: allow more fine grained SSL SNI vhost check
to avoid unnecessary 421 errors after CVE-2025-23048 fix
-
Fri Oct 24 2025 Luboš Uhliarik <luhliari@redhat.com> - 2.4.63-6
- Resolves: RHEL-122290 - mod_proxy_hcheck may stop healthchecks after a child
process is reclaimed
-
Mon Sep 08 2025 Luboš Uhliarik <luhliari@redhat.com> - 2.4.63-5
- Resolves: RHEL-92663 - Image mode: The dir /var/www is not created when
updating system in image mode
-
Sat Aug 16 2025 Luboš Uhliarik <luhliari@redhat.com> - 2.4.63-4
- Resolves: RHEL-99945 - httpd: HTTP Session Hijack via a TLS
upgrade (CVE-2025-49812)
- Resolves: RHEL-99962 - httpd: access control bypass by trusted clients
is possible using TLS 1.3 session resumption (CVE-2025-23048)
- Resolves: RHEL-99970 - httpd: insufficient escaping of user-supplied
data in mod_ssl (CVE-2024-47252)
- Resolves: RHEL-103489 - stickysession field does not work when
specifying it in the query parameter after upgrade to 9.5