USN-8571-1: Apache HTTP Server vulnerabilities

Publication date

20 July 2026

Overview

Several security issues were fixed in Apache HTTP Server.


Packages

Details

Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server
incorrectly handled certain memory operations in mod_authn_socache. A
remote attacker could possibly use this issue to cause a denial of service.
(CVE-2026-33007)

Haruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache
HTTP Server had an HTTP response splitting vulnerability in multiple
modules when used with untrusted or compromised backend servers. An
attacker could possibly use this issue to inject arbitrary HTTP headers.
(CVE-2026-33523)

Elhanan Haenel discovered that Apache HTTP Server incorrectly handled
certain memory operations in mod_proxy_ajp. A remote attacker could
possibly use this issue to cause a denial of service. (CVE-2026-33857)

Tianshuo Han and Jérôme Djouder discovered that Apache HTTP...

Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server
incorrectly handled certain memory operations in mod_authn_socache. A
remote attacker could possibly use this issue to cause a denial of service.
(CVE-2026-33007)

Haruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache
HTTP Server had an HTTP response splitting vulnerability in multiple
modules when used with untrusted or compromised backend servers. An
attacker could possibly use this issue to inject arbitrary HTTP headers.
(CVE-2026-33523)

Elhanan Haenel discovered that Apache HTTP Server incorrectly handled
certain memory operations in mod_proxy_ajp. A remote attacker could
possibly use this issue to cause a denial of service. (CVE-2026-33857)

Tianshuo Han and Jérôme Djouder discovered that Apache HTTP Server
incorrectly handled certain string operations in mod_proxy_ajp. A remote
attacker could possibly use this issue to obtain sensitive information.
(CVE-2026-34032)

It was discovered that Apache HTTP Server's mod_proxy_html module
incorrectly handled certain content from an untrusted backend. A remote
attacker could possibly use this issue to cause a denial of service.
(CVE-2026-34355)

It was discovered that Apache HTTP Server incorrectly handled
ProxyPassReverseCookie directives with a malicious backend server. A
remote attacker could possibly use this issue to cause a denial of service.
(CVE-2026-34356)

It was discovered that Apache HTTP Server's mod_dav_fs module incorrectly
handled certain path operations. An authenticated user could possibly use
this issue to manipulate trusted WebDAV property databases or cause a
denial of service. (CVE-2026-42535)

It was discovered that Apache HTTP Server's mod_xml2enc module incorrectly
handled certain content from an untrusted backend. A remote attacker could
possibly use this issue to cause a denial of service. (CVE-2026-42536)

It was discovered that Apache HTTP Server incorrectly handled response
headers when multiple content languages were configured. A remote
attacker could possibly use this issue to obtain sensitive information.
(CVE-2026-43951)

It was discovered that Apache HTTP Server incorrectly restricted certain
file functions in expressions within .htaccess files. A local attacker
with .htaccess write access could possibly use this issue to obtain
sensitive information. (CVE-2026-44119)

It was discovered that Apache HTTP Server's mod_ssl module incorrectly
handled OCSP responses from an attacker-controlled server. A remote
attacker could possibly use this issue to obtain sensitive information or
cause a denial of service. (CVE-2026-44185)

It was discovered that Apache HTTP Server's mod_proxy_ftp module
incorrectly handled responses from an attacker-controlled backend FTP
server. A remote attacker could possibly use this issue to cause a denial
of service. (CVE-2026-44186)

It was discovered that Apache HTTP Server incorrectly handled crafted
regular expressions in the server configuration. An attacker could
possibly use this issue to execute arbitrary code or cause a denial of
service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and
Ubuntu 20.04 LTS. (CVE-2026-44631)

It was discovered that Apache HTTP Server's mod_http2 module had a
use-after-free vulnerability when file handles were exhausted. A remote
attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 20.04 LTS. (CVE-2026-48913)


Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
20.04 LTS focal apache2 –  2.4.41-4ubuntu3.23+esm5  
apache2-bin –  2.4.41-4ubuntu3.23+esm5  
apache2-dev –  2.4.41-4ubuntu3.23+esm5  
apache2-ssl-dev –  2.4.41-4ubuntu3.23+esm5  
apache2-suexec-custom –  2.4.41-4ubuntu3.23+esm5  
apache2-suexec-pristine –  2.4.41-4ubuntu3.23+esm5  
apache2-utils –  2.4.41-4ubuntu3.23+esm5  
libapache2-mod-md –  2.4.41-4ubuntu3.23+esm5  
libapache2-mod-proxy-uwsgi –  2.4.41-4ubuntu3.23+esm5  
18.04 LTS bionic apache2 –  2.4.29-1ubuntu4.27+esm10  
apache2-bin –  2.4.29-1ubuntu4.27+esm10  
apache2-dev –  2.4.29-1ubuntu4.27+esm10  
apache2-ssl-dev –  2.4.29-1ubuntu4.27+esm10  
apache2-suexec-custom –  2.4.29-1ubuntu4.27+esm10  
apache2-suexec-pristine –  2.4.29-1ubuntu4.27+esm10  
apache2-utils –  2.4.29-1ubuntu4.27+esm10  
16.04 LTS xenial apache2 –  2.4.18-2ubuntu3.17+esm19  
apache2-bin –  2.4.18-2ubuntu3.17+esm19  
apache2-dev –  2.4.18-2ubuntu3.17+esm19  
apache2-suexec-custom –  2.4.18-2ubuntu3.17+esm19  
apache2-suexec-pristine –  2.4.18-2ubuntu3.17+esm19  
apache2-utils –  2.4.18-2ubuntu3.17+esm19  
14.04 LTS trusty apache2 –  2.4.7-1ubuntu4.22+esm14  
apache2-bin –  2.4.7-1ubuntu4.22+esm14  
apache2-dev –  2.4.7-1ubuntu4.22+esm14  
apache2-mpm-event –  2.4.7-1ubuntu4.22+esm14  
apache2-mpm-itk –  2.4.7-1ubuntu4.22+esm14  
apache2-mpm-prefork –  2.4.7-1ubuntu4.22+esm14  
apache2-mpm-worker –  2.4.7-1ubuntu4.22+esm14  
apache2-suexec –  2.4.7-1ubuntu4.22+esm14  
apache2-suexec-custom –  2.4.7-1ubuntu4.22+esm14  
apache2-suexec-pristine –  2.4.7-1ubuntu4.22+esm14  
apache2-utils –  2.4.7-1ubuntu4.22+esm14  
apache2.2-bin –  2.4.7-1ubuntu4.22+esm14  
libapache2-mod-macro –  1:2.4.7-1ubuntu4.22+esm14  
libapache2-mod-proxy-html –  1:2.4.7-1ubuntu4.22+esm14  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›