[ GLSA 202608-05 ] Apache HTTPD: Multiple Vulnerabilities

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <178666552910.1.4323389899130997890@ea9ff15b5095>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202608-05
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: High
    Title: Apache HTTPD: Multiple Vulnerabilities
     Date: August 13, 2026
     Bugs: #915996, #959821, #967089, #973625, #977098
       ID: 202608-05

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been found in Apache HTTPD, the worst of
which could result in remote code execution.

Background
==========

The Apache HTTP server is one of the most popular web servers on the
Internet.

Affected packages
=================

Package             Vulnerable    Unaffected
------------------  ------------  ------------
www-servers/apache  < 2.4.68      >= 2.4.68

Description
===========

Multiple vulnerabilities have been discovered in Apache HTTPD. Please
review the CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All Apache HTTPD users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=www-servers/apache-2.4.68"

References
==========

[ 1 ] CVE-2023-31122
      https://nvd.nist.gov/vuln/detail/CVE-2023-31122
[ 2 ] CVE-2023-43622
      https://nvd.nist.gov/vuln/detail/CVE-2023-43622
[ 3 ] CVE-2023-44487
      https://nvd.nist.gov/vuln/detail/CVE-2023-44487
[ 4 ] CVE-2023-45802
      https://nvd.nist.gov/vuln/detail/CVE-2023-45802
[ 5 ] CVE-2024-42516
      https://nvd.nist.gov/vuln/detail/CVE-2024-42516
[ 6 ] CVE-2024-43204
      https://nvd.nist.gov/vuln/detail/CVE-2024-43204
[ 7 ] CVE-2024-43394
      https://nvd.nist.gov/vuln/detail/CVE-2024-43394
[ 8 ] CVE-2024-47252
      https://nvd.nist.gov/vuln/detail/CVE-2024-47252
[ 9 ] CVE-2025-23048
      https://nvd.nist.gov/vuln/detail/CVE-2025-23048
[ 10 ] CVE-2025-49630
      https://nvd.nist.gov/vuln/detail/CVE-2025-49630
[ 11 ] CVE-2025-49812
      https://nvd.nist.gov/vuln/detail/CVE-2025-49812
[ 12 ] CVE-2025-53020
      https://nvd.nist.gov/vuln/detail/CVE-2025-53020
[ 13 ] CVE-2025-55753
      https://nvd.nist.gov/vuln/detail/CVE-2025-55753
[ 14 ] CVE-2025-58098
      https://nvd.nist.gov/vuln/detail/CVE-2025-58098
[ 15 ] CVE-2025-59775
      https://nvd.nist.gov/vuln/detail/CVE-2025-59775
[ 16 ] CVE-2025-65082
      https://nvd.nist.gov/vuln/detail/CVE-2025-65082
[ 17 ] CVE-2025-66200
      https://nvd.nist.gov/vuln/detail/CVE-2025-66200
[ 18 ] CVE-2026-23918
      https://nvd.nist.gov/vuln/detail/CVE-2026-23918
[ 19 ] CVE-2026-24072
      https://nvd.nist.gov/vuln/detail/CVE-2026-24072
[ 20 ] CVE-2026-28780
      https://nvd.nist.gov/vuln/detail/CVE-2026-28780
[ 21 ] CVE-2026-29167
      https://nvd.nist.gov/vuln/detail/CVE-2026-29167
[ 22 ] CVE-2026-29168
      https://nvd.nist.gov/vuln/detail/CVE-2026-29168
[ 23 ] CVE-2026-29169
      https://nvd.nist.gov/vuln/detail/CVE-2026-29169
[ 24 ] CVE-2026-29170
      https://nvd.nist.gov/vuln/detail/CVE-2026-29170
[ 25 ] CVE-2026-33006
      https://nvd.nist.gov/vuln/detail/CVE-2026-33006
[ 26 ] CVE-2026-33007
      https://nvd.nist.gov/vuln/detail/CVE-2026-33007
[ 27 ] CVE-2026-33523
      https://nvd.nist.gov/vuln/detail/CVE-2026-33523
[ 28 ] CVE-2026-33857
      https://nvd.nist.gov/vuln/detail/CVE-2026-33857
[ 29 ] CVE-2026-34032
      https://nvd.nist.gov/vuln/detail/CVE-2026-34032
[ 30 ] CVE-2026-34059
      https://nvd.nist.gov/vuln/detail/CVE-2026-34059
[ 31 ] CVE-2026-34355
      https://nvd.nist.gov/vuln/detail/CVE-2026-34355
[ 32 ] CVE-2026-34356
      https://nvd.nist.gov/vuln/detail/CVE-2026-34356
[ 33 ] CVE-2026-42535
      https://nvd.nist.gov/vuln/detail/CVE-2026-42535
[ 34 ] CVE-2026-42536
      https://nvd.nist.gov/vuln/detail/CVE-2026-42536
[ 35 ] CVE-2026-43951
      https://nvd.nist.gov/vuln/detail/CVE-2026-43951
[ 36 ] CVE-2026-44119
      https://nvd.nist.gov/vuln/detail/CVE-2026-44119
[ 37 ] CVE-2026-44185
      https://nvd.nist.gov/vuln/detail/CVE-2026-44185
[ 38 ] CVE-2026-44186
      https://nvd.nist.gov/vuln/detail/CVE-2026-44186
[ 39 ] CVE-2026-44631
      https://nvd.nist.gov/vuln/detail/CVE-2026-44631
[ 40 ] CVE-2026-48913
      https://nvd.nist.gov/vuln/detail/CVE-2026-48913
[ 41 ] CVE-2026-49975
      https://nvd.nist.gov/vuln/detail/CVE-2026-49975

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202608-05

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2026 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 870 B)
-----BEGIN PGP SIGNATURE-----

iQJPBAEBCAA5FiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmp+WjgbFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMiwyAAoJEBTEJDmlcvvZDeAP/2s8S//FG724nwHxFPRi
mLFMKy0MdhmMhILXy05zQlqo574OdQN8xvl+L1cX2/vRmbVlZ65rx+Iq3dBXazig
vNM3czwVRkhw7c5oExd3ItGKGlMK0NTyAYxkWKg0vHNNnjmavnHQwhqM9N/LdwxX
18fIFxfQZfHryOU0L8PeJKxo9GCo3Ajf+Xz554T6tdNu0lyp6AsWTOiyIfoLJy7s
3S+yNVRGs1oXCJwrJGvBvIzHo0D8hb4umgYrcAT9vRExw77S5T8YWvN00sO0TZDC
bTrZNY+ZH+rQHh6QAmsmqXn1qNU3kckZ0UWIHYdz3TyiOERbdkEEaSZkx2okX0PL
zNUgEnotaJhPlmCF+kQefcIPEekvPLYnnbcZ14N1dwcKSAbA5KyFdOqeXJeSnEw2
0MD6pZuwQk6eHtgE+t3kAlkMuuBC7fjE65iwPwYCVPlur+p4kAhAwoA+mP1GNvM4
qArEcgpuYlgRKRXrmZoFPFy0X83ayogrvhFCvTiEgCTpQWLdPfZxLUDShkp6cwVi
veo2omKD/hpcrk1MXzuNiO4/z50HB0GAReuq80yKYhcggUx6tBRwhrJo1S14HrZ3
g7I5yOBaNJFPnUC5Vxpk/Vx3JnEEGz2/A7hmqc6L/vhBX8mh79qRuSW4JdSvmPcG
vS5Rf77dRfaSB5uad7XcgjnV
=BfT6
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.