{"id":"RHSA-2026:27200","summary":"Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.62 SP4 security update","modified":"2026-06-23T10:15:13.907808525Z","published":"2026-06-23T10:07:41Z","upstream":["CVE-2025-53020","CVE-2026-27135","CVE-2026-28780","CVE-2026-29168","CVE-2026-29169","CVE-2026-33007","CVE-2026-33857","CVE-2026-34032","CVE-2026-34059","CVE-2026-49975"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:27200"},{"type":"ARTICLE","url":"https://access.redhat.com/security/updates/classification/#important"},{"type":"ARTICLE","url":"https://docs.redhat.com/en/documentation/red_hat_jboss_core_services/2.4.62/html/red_hat_jboss_core_services_apache_http_server_2.4.62_service_pack_4_release_notes/index"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2379343"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2448754"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2464940"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2464952"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2464953"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2465296"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2465299"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2466753"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2466913"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2485371"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_27200.json"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2025-53020"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2025-53020"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53020"},{"type":"ARTICLE","url":"https://httpd.apache.org/security/vulnerabilities_24.html"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-27135"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-27135"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27135"},{"type":"ARTICLE","url":"https://github.com/nghttp2/nghttp2/commit/5c7df8fa815ac1004d9ecb9d1f7595c4d37f46e1"},{"type":"ARTICLE","url":"https://github.com/nghttp2/nghttp2/security/advisories/GHSA-6933-cjhr-5qg6"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-28780"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-28780"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28780"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-29168"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-29168"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-29168"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-29169"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-29169"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-29169"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-33007"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-33007"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33007"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-33857"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-33857"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33857"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-34032"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-34032"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34032"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-34059"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-34059"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34059"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-49975"},{"type":"ARTICLE","url":"https://access.redhat.com/security/vulnerabilities/RHSB-2026-007"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-49975"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49975"},{"type":"ARTICLE","url":"https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb"}],"affected":[{"package":{"name":"jbcs-httpd24-httpd","ecosystem":"Red Hat:jboss_core_services:1::el7","purl":"pkg:rpm/redhat/jbcs-httpd24-httpd"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.4.62-13.el7jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-httpd-debuginfo","ecosystem":"Red Hat:jboss_core_services:1::el7","purl":"pkg:rpm/redhat/jbcs-httpd24-httpd-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.4.62-13.el7jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-httpd-devel","ecosystem":"Red Hat:jboss_core_services:1::el7","purl":"pkg:rpm/redhat/jbcs-httpd24-httpd-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.4.62-13.el7jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-httpd-manual","ecosystem":"Red Hat:jboss_core_services:1::el7","purl":"pkg:rpm/redhat/jbcs-httpd24-httpd-manual"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.4.62-13.el7jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-httpd-selinux","ecosystem":"Red Hat:jboss_core_services:1::el7","purl":"pkg:rpm/redhat/jbcs-httpd24-httpd-selinux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.4.62-13.el7jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-httpd-tools","ecosystem":"Red Hat:jboss_core_services:1::el7","purl":"pkg:rpm/redhat/jbcs-httpd24-httpd-tools"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.4.62-13.el7jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-mod_http2","ecosystem":"Red Hat:jboss_core_services:1::el7","purl":"pkg:rpm/redhat/jbcs-httpd24-mod_http2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.0.29-10.el7jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-mod_http2-debuginfo","ecosystem":"Red Hat:jboss_core_services:1::el7","purl":"pkg:rpm/redhat/jbcs-httpd24-mod_http2-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.0.29-10.el7jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-mod_ldap","ecosystem":"Red Hat:jboss_core_services:1::el7","purl":"pkg:rpm/redhat/jbcs-httpd24-mod_ldap"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.4.62-13.el7jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-mod_proxy_html","ecosystem":"Red Hat:jboss_core_services:1::el7","purl":"pkg:rpm/redhat/jbcs-httpd24-mod_proxy_html"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.4.62-13.el7jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-mod_session","ecosystem":"Red Hat:jboss_core_services:1::el7","purl":"pkg:rpm/redhat/jbcs-httpd24-mod_session"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.4.62-13.el7jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-mod_ssl","ecosystem":"Red Hat:jboss_core_services:1::el7","purl":"pkg:rpm/redhat/jbcs-httpd24-mod_ssl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.4.62-13.el7jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-httpd","ecosystem":"Red Hat:jboss_core_services:1::el8","purl":"pkg:rpm/redhat/jbcs-httpd24-httpd"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.4.62-13.el8jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-httpd-debuginfo","ecosystem":"Red Hat:jboss_core_services:1::el8","purl":"pkg:rpm/redhat/jbcs-httpd24-httpd-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.4.62-13.el8jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-httpd-devel","ecosystem":"Red Hat:jboss_core_services:1::el8","purl":"pkg:rpm/redhat/jbcs-httpd24-httpd-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.4.62-13.el8jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-httpd-manual","ecosystem":"Red Hat:jboss_core_services:1::el8","purl":"pkg:rpm/redhat/jbcs-httpd24-httpd-manual"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.4.62-13.el8jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-httpd-selinux","ecosystem":"Red Hat:jboss_core_services:1::el8","purl":"pkg:rpm/redhat/jbcs-httpd24-httpd-selinux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.4.62-13.el8jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-httpd-tools","ecosystem":"Red Hat:jboss_core_services:1::el8","purl":"pkg:rpm/redhat/jbcs-httpd24-httpd-tools"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.4.62-13.el8jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-httpd-tools-debuginfo","ecosystem":"Red Hat:jboss_core_services:1::el8","purl":"pkg:rpm/redhat/jbcs-httpd24-httpd-tools-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.4.62-13.el8jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-mod_http2","ecosystem":"Red Hat:jboss_core_services:1::el8","purl":"pkg:rpm/redhat/jbcs-httpd24-mod_http2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.0.29-10.el8jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-mod_http2-debuginfo","ecosystem":"Red Hat:jboss_core_services:1::el8","purl":"pkg:rpm/redhat/jbcs-httpd24-mod_http2-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.0.29-10.el8jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-mod_ldap","ecosystem":"Red Hat:jboss_core_services:1::el8","purl":"pkg:rpm/redhat/jbcs-httpd24-mod_ldap"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.4.62-13.el8jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-mod_ldap-debuginfo","ecosystem":"Red Hat:jboss_core_services:1::el8","purl":"pkg:rpm/redhat/jbcs-httpd24-mod_ldap-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.4.62-13.el8jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-mod_proxy_html","ecosystem":"Red Hat:jboss_core_services:1::el8","purl":"pkg:rpm/redhat/jbcs-httpd24-mod_proxy_html"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.4.62-13.el8jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-mod_proxy_html-debuginfo","ecosystem":"Red Hat:jboss_core_services:1::el8","purl":"pkg:rpm/redhat/jbcs-httpd24-mod_proxy_html-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.4.62-13.el8jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-mod_session","ecosystem":"Red Hat:jboss_core_services:1::el8","purl":"pkg:rpm/redhat/jbcs-httpd24-mod_session"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.4.62-13.el8jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-mod_session-debuginfo","ecosystem":"Red Hat:jboss_core_services:1::el8","purl":"pkg:rpm/redhat/jbcs-httpd24-mod_session-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.4.62-13.el8jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-mod_ssl","ecosystem":"Red Hat:jboss_core_services:1::el8","purl":"pkg:rpm/redhat/jbcs-httpd24-mod_ssl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.4.62-13.el8jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-mod_ssl-debuginfo","ecosystem":"Red Hat:jboss_core_services:1::el8","purl":"pkg:rpm/redhat/jbcs-httpd24-mod_ssl-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.4.62-13.el8jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-nghttp2","ecosystem":"Red Hat:jboss_core_services:1::el7","purl":"pkg:rpm/redhat/jbcs-httpd24-nghttp2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.64.0-3.el7jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-nghttp2-debuginfo","ecosystem":"Red Hat:jboss_core_services:1::el7","purl":"pkg:rpm/redhat/jbcs-httpd24-nghttp2-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.64.0-3.el7jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-nghttp2-devel","ecosystem":"Red Hat:jboss_core_services:1::el7","purl":"pkg:rpm/redhat/jbcs-httpd24-nghttp2-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.64.0-3.el7jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-nghttp2","ecosystem":"Red Hat:jboss_core_services:1::el8","purl":"pkg:rpm/redhat/jbcs-httpd24-nghttp2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.64.0-3.el8jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-nghttp2-debuginfo","ecosystem":"Red Hat:jboss_core_services:1::el8","purl":"pkg:rpm/redhat/jbcs-httpd24-nghttp2-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.64.0-3.el8jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-nghttp2-devel","ecosystem":"Red Hat:jboss_core_services:1::el8","purl":"pkg:rpm/redhat/jbcs-httpd24-nghttp2-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.64.0-3.el8jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-mod_md","ecosystem":"Red Hat:jboss_core_services:1::el7","purl":"pkg:rpm/redhat/jbcs-httpd24-mod_md"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.4.28-16.el7jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-mod_md-debuginfo","ecosystem":"Red Hat:jboss_core_services:1::el7","purl":"pkg:rpm/redhat/jbcs-httpd24-mod_md-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.4.28-16.el7jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-mod_md","ecosystem":"Red Hat:jboss_core_services:1::el8","purl":"pkg:rpm/redhat/jbcs-httpd24-mod_md"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.4.28-16.el8jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}},{"package":{"name":"jbcs-httpd24-mod_md-debuginfo","ecosystem":"Red Hat:jboss_core_services:1::el8","purl":"pkg:rpm/redhat/jbcs-httpd24-mod_md-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.4.28-16.el8jbcs"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:27200.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"}]}