## This update for apache2 fixes the following issues * CVE-2026-23918: http2: double free and possible RCE on early reset (bsc#1263957). * CVE-2026-24072: mod_rewrite elevation of privileges via ap_expr (bsc#1263935). * CVE-2026-28780: heap buffer overflow in `mod_proxy_ajp` via `ajp_msg_check_header()` (bsc#1264163). * CVE-2026-29167: mod_ldap per-dir use-after-free (bsc#1267976). * CVE-2026-29168: allocation of resources without limits in `mod_md` via OCSP response (bsc#1264150). * CVE-2026-29169: NULL pointer dereference in `mod_dav_lock` allows server crash via malicious requests (bsc#1263956). * CVE-2026-29170: mod_proxy_ftp XSS (bsc#1267977). * CVE-2026-33006: `mod_auth_digest` timing attack allows bypass of Digest authentication (bsc#1263955).
* bsc#1207327
* bsc#1208708
* bsc#1214357
* bsc#1263935
* bsc#1263950
* bsc#1263951
* bsc#1263952
* bsc#1263953
* bsc#1263954
* bsc#1263955
* bsc#1263956
* bsc#1263957
* bsc#1264150
* bsc#1264163
* bsc#1267503
* bsc#1267955
* bsc#1267956
* bsc#1267962
* bsc#1267963
* bsc#1267965
* bsc#1267969
* bsc#1267970
* bsc#1267971
* bsc#1267972
* bsc#1267976
* bsc#1267977
* bsc#1267978
* bsc#690734
* jsc#PED-16334
Cross-
* CVE-2006-20001
* CVE-2021-44224
* CVE-2021-44790
* CVE-2022-22719
* CVE-2022-22720
* CVE-2022-22721
* CVE-2022-23943
* CVE-2022-26377
* CVE-2022-28614
* CVE-2022-28615
* CVE-2022-29404
* CVE-2022-30522
* CVE-2022-30556
* CVE-2022-31813
* CVE-2022-36760
* CVE-2022-37436
* CVE-2023-25690
* CVE-2023-27522
* CVE-2023-31122
* CVE-2023-38709
* CVE-2023-45802
* CVE-2024-24795
* CVE-2024-27316
Get the latest Linux and open source security news straight to your inbox.