[CLSA-2026:1777945456] httpd: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-05-05 01:44:21 UTC
Description:
- CVE-2024-42516: fix HTTP response splitting in core httpd via header merging refactor in modules/http/http_filters.c - CVE-2024-43204: fix SSRF in mod_proxy when mod_headers is configured to modify Content-Type from request input
Updated packages:
  • httpd-2.4.53-11.el9_2.5.tuxcare.els11.x86_64.rpm
    sha:b9376bcd61aef67085c26aafe3c516f87aa4b4bff79b4d8ed0bba94c586de734
  • httpd-core-2.4.53-11.el9_2.5.tuxcare.els11.x86_64.rpm
    sha:07c6169c3663e70a16fcfaae83120e6614d924af79e88dc608e2452aa17326c1
  • httpd-devel-2.4.53-11.el9_2.5.tuxcare.els11.x86_64.rpm
    sha:54ed7919583d288b58006c3c62260bcfcc335653688312f8e11568cdd94480a5
  • httpd-filesystem-2.4.53-11.el9_2.5.tuxcare.els11.noarch.rpm
    sha:132aaa008a8b0bcea4fe6fc86110781ae4f29ea4e8e69a6491ce9f8125b1c07b
  • httpd-manual-2.4.53-11.el9_2.5.tuxcare.els11.noarch.rpm
    sha:264025dcd40483f8958b679425ebebfafdc5de7249956056fec79a2481ef3b43
  • httpd-tools-2.4.53-11.el9_2.5.tuxcare.els11.x86_64.rpm
    sha:c082f6d92f210e83d7033ae473f938f0374963701d509b5507df95a9b13ee2be
  • mod_ldap-2.4.53-11.el9_2.5.tuxcare.els11.x86_64.rpm
    sha:46bc8e429cca82eaf0d9dae941cfe3848bf71c4aaa490cde4f1f9a8a7321b32c
  • mod_lua-2.4.53-11.el9_2.5.tuxcare.els11.x86_64.rpm
    sha:5c8b15ab732a572f1ba076af856bf68668faa900a87cf4ef6535a321b2fefd73
  • mod_proxy_html-2.4.53-11.el9_2.5.tuxcare.els11.x86_64.rpm
    sha:42785dcaa8c7efb14a3692a8bc80d71659e7f747c093264d8fcb5e95d5af01a9
  • mod_session-2.4.53-11.el9_2.5.tuxcare.els11.x86_64.rpm
    sha:1571cb78bd770e4d05fa8e804ce961f8595bff14786056fedb33af52d97777dc
  • mod_ssl-2.4.53-11.el9_2.5.tuxcare.els11.x86_64.rpm
    sha:8e0c0a54f94b11a1b90ac1d8f4b87ba75e717301593d4d62c9cd53cd2336d3e7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.