Skip to content
SUSE Apache2 Important Update Addresses 66 Vulnerabilities 2026-2686

SUSE Apache2 Important Update Addresses 66 Vulnerabilities 2026-2686

Linuxsecurity LinuxSecurity Advisories June 30, 2026

## This update for apache2 fixes the following issues * CVE-2026-23918: http2: double free and possible RCE on early reset (bsc#1263957). * CVE-2026-24072: mod_rewrite elevation of privileges via ap_expr (bsc#1263935). * CVE-2026-28780: heap buffer overflow in `mod_proxy_ajp` via `ajp_msg_check_header()` (bsc#1264163). * CVE-2026-29167: mod_ldap per-dir use-after-free (bsc#1267976). * CVE-2026-29168: allocation of resources without limits in `mod_md` via OCSP response (bsc#1264150). * CVE-2026-29169: NULL pointer dereference in `mod_dav_lock` allows server crash via malicious requests (bsc#1263956). * CVE-2026-29170: mod_proxy_ftp XSS (bsc#1267977). * CVE-2026-33006: `mod_auth_digest` timing attack allows bypass of Digest authentication (bsc#1263955).

## This update for apache2 fixes the following issues * CVE-2026-23918: http2: double free and possible RCE on early reset (bsc#1263957). * CVE-2026-24072: mod_rewrite elevation of privileges via ap_expr (bsc#1263935). * CVE-2026-28780: heap buffer overflow in `mod_proxy_ajp` via `ajp_msg_check_header()` (bsc#1264163). * CVE-2026-29167: mod_ldap per-dir use-after-free (bsc#1267976). * CVE-2026-29168: allocation of resources without limits in `mod_md` via OCSP response (bsc#1264150). * CVE-2026-29169: NULL pointer dereference in `mod_dav_lock` allows server crash via malicious requests (bsc#1263956). * CVE-2026-29170: mod_proxy_ftp XSS (bsc#1267977). * CVE-2026-33006: `mod_auth_digest` timing attack allows bypass of Digest authentication (bsc#1263955).

Announcement ID: SUSE-SU-2026:2686-1 Release Date: 2026-06-29T22:36:09Z Rating: important

Get the latest Linux and open source security news straight to your inbox.