• imports/c10s/httpd-2.4.63-14.el10 70c1111736

    Ghost released this 2026-05-29 09:32:09 +00:00 | -721 commits to c8-stream-2.4 since this release

    code execution via heap-based buffer overflow (CVE-2026-28780)
    Resolves: RHEL-175064 - httpd: NULL pointer dereference can cause a child
    process crash (CVE-2026-33007)
    Resolves: RHEL-175087 - httpd: off-by-one out-of-bounds reads in AJP getter
    functions (CVE-2026-33857)
    Resolves: RHEL-175044 - httpd: heap-based buffer over-read due to missing
    null-termination check (CVE-2026-34032)
    Resolves: RHEL-175060 - httpd: heap-based buffer over-read and memory
    disclosure in ajp_parse_data() (CVE-2026-34059)

    Downloads