Home / mailingsPDF  

[USN-8571-1] Apache HTTP Server vulnerabilities

Posted on 21 July 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8571-1
July 20, 2026

apache2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in Apache HTTP Server.

Software Description:
- apache2: Apache HTTP server

Details:

Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server
incorrectly handled certain memory operations in mod_authn_socache. A
remote attacker could possibly use this issue to cause a denial of service.
(CVE-2026-33007)

Haruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache
HTTP Server had an HTTP response splitting vulnerability in multiple
modules when used with untrusted or compromised backend servers. An
attacker could possibly use this issue to inject arbitrary HTTP headers.
(CVE-2026-33523)

Elhanan Haenel discovered that Apache HTTP Server incorrectly handled
certain memory operations in mod_proxy_ajp. A remote attacker could
possibly use this issue to cause a denial of service. (CVE-2026-33857)

Tianshuo Han and Jérôme Djouder discovered that Apache HTTP Server
incorrectly handled certain string operations in mod_proxy_ajp. A remote
attacker could possibly use this issue to obtain sensitive information.
(CVE-2026-34032)

It was discovered that Apache HTTP Server's mod_proxy_html module
incorrectly handled certain content from an untrusted backend. A remote
attacker could possibly use this issue to cause a denial of service.
(CVE-2026-34355)

It was discovered that Apache HTTP Server incorrectly handled
ProxyPassReverseCookie directives with a malicious backend server. A
remote attacker could possibly use this issue to cause a denial of service.
(CVE-2026-34356)

It was discovered that Apache HTTP Server's mod_dav_fs module incorrectly
handled certain path operations. An authenticated user could possibly use
this issue to manipulate trusted WebDAV property databases or cause a
denial of service. (CVE-2026-42535)

It was discovered that Apache HTTP Server's mod_xml2enc module incorrectly
handled certain content from an untrusted backend. A remote attacker could
possibly use this issue to cause a denial of service. (CVE-2026-42536)

It was discovered that Apache HTTP Server incorrectly handled response
headers when multiple content languages were configured. A remote
attacker could possibly use this issue to obtain sensitive information.
(CVE-2026-43951)

It was discovered that Apache HTTP Server incorrectly restricted certain
file functions in expressions within .htaccess files. A local attacker
with .htaccess write access could possibly use this issue to obtain
sensitive information. (CVE-2026-44119)

It was discovered that Apache HTTP Server's mod_ssl module incorrectly
handled OCSP responses from an attacker-controlled server. A remote
attacker could possibly use this issue to obtain sensitive information or
cause a denial of service. (CVE-2026-44185)

It was discovered that Apache HTTP Server's mod_proxy_ftp module
incorrectly handled responses from an attacker-controlled backend FTP
server. A remote attacker could possibly use this issue to cause a denial
of service. (CVE-2026-44186)

It was discovered that Apache HTTP Server incorrectly handled crafted
regular expressions in the server configuration. An attacker could
possibly use this issue to execute arbitrary code or cause a denial of
service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and
Ubuntu 20.04 LTS. (CVE-2026-44631)

It was discovered that Apache HTTP Server's mod_http2 module had a
use-after-free vulnerability when file handles were exhausted. A remote
attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 20.04 LTS. (CVE-2026-48913)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS
apache2 2.4.41-4ubuntu3.23+esm5
Available with Ubuntu Pro
apache2-bin 2.4.41-4ubuntu3.23+esm5
Available with Ubuntu Pro
apache2-dev 2.4.41-4ubuntu3.23+esm5
Available with Ubuntu Pro
apache2-ssl-dev 2.4.41-4ubuntu3.23+esm5
Available with Ubuntu Pro
apache2-suexec-custom 2.4.41-4ubuntu3.23+esm5
Available with Ubuntu Pro
apache2-suexec-pristine 2.4.41-4ubuntu3.23+esm5
Available with Ubuntu Pro
apache2-utils 2.4.41-4ubuntu3.23+esm5
Available with Ubuntu Pro
libapache2-mod-md 2.4.41-4ubuntu3.23+esm5
Available with Ubuntu Pro
libapache2-mod-proxy-uwsgi 2.4.41-4ubuntu3.23+esm5
Available with Ubuntu Pro

Ubuntu 18.04 LTS
apache2 2.4.29-1ubuntu4.27+esm10
Available with Ubuntu Pro
apache2-bin 2.4.29-1ubuntu4.27+esm10
Available with Ubuntu Pro
apache2-dev 2.4.29-1ubuntu4.27+esm10
Available with Ubuntu Pro
apache2-ssl-dev 2.4.29-1ubuntu4.27+esm10
Available with Ubuntu Pro
apache2-suexec-custom 2.4.29-1ubuntu4.27+esm10
Available with Ubuntu Pro
apache2-suexec-pristine 2.4.29-1ubuntu4.27+esm10
Available with Ubuntu Pro
apache2-utils 2.4.29-1ubuntu4.27+esm10
Available with Ubuntu Pro

Ubuntu 16.04 LTS
apache2 2.4.18-2ubuntu3.17+esm19
Available with Ubuntu Pro
apache2-bin 2.4.18-2ubuntu3.17+esm19
Available with Ubuntu Pro
apache2-dev 2.4.18-2ubuntu3.17+esm19
Available with Ubuntu Pro
apache2-suexec-custom 2.4.18-2ubuntu3.17+esm19
Available with Ubuntu Pro
apache2-suexec-pristine 2.4.18-2ubuntu3.17+esm19
Available with Ubuntu Pro
apache2-utils 2.4.18-2ubuntu3.17+esm19
Available with Ubuntu Pro

Ubuntu 14.04 LTS
apache2 2.4.7-1ubuntu4.22+esm14
Available with Ubuntu Pro
apache2-bin 2.4.7-1ubuntu4.22+esm14
Available with Ubuntu Pro
apache2-dev 2.4.7-1ubuntu4.22+esm14
Available with Ubuntu Pro
apache2-mpm-event 2.4.7-1ubuntu4.22+esm14
Available with Ubuntu Pro
apache2-mpm-itk 2.4.7-1ubuntu4.22+esm14
Available with Ubuntu Pro
apache2-mpm-prefork 2.4.7-1ubuntu4.22+esm14
Available with Ubuntu Pro
apache2-mpm-worker 2.4.7-1ubuntu4.22+esm14
Available with Ubuntu Pro
apache2-suexec 2.4.7-1ubuntu4.22+esm14
Available with Ubuntu Pro
apache2-suexec-custom 2.4.7-1ubuntu4.22+esm14
Available with Ubuntu Pro
apache2-suexec-pristine 2.4.7-1ubuntu4.22+esm14
Available with Ubuntu Pro
apache2-utils 2.4.7-1ubuntu4.22+esm14
Available with Ubuntu Pro
apache2.2-bin 2.4.7-1ubuntu4.22+esm14
Available with Ubuntu Pro
libapache2-mod-macro 1:2.4.7-1ubuntu4.22+esm14
Available with Ubuntu Pro
libapache2-mod-proxy-html 1:2.4.7-1ubuntu4.22+esm14
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8571-1
CVE-2026-33007, CVE-2026-33523, CVE-2026-33857, CVE-2026-34032,
CVE-2026-34355, CVE-2026-34356, CVE-2026-42535, CVE-2026-42536,
CVE-2026-43951, CVE-2026-44119, CVE-2026-44185, CVE-2026-44186,
CVE-2026-44631, CVE-2026-48913, CVE-2026-49975

--===============2601849677701733049==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP