{"schema_version":"1.7.5","id":"SUSE-SU-2026:2686-1","published":"2026-06-29T22:36:03Z","modified":"2026-07-01T09:45:04.712117752Z","related":["CVE-2006-20001","CVE-2021-44224","CVE-2021-44790","CVE-2022-22719","CVE-2022-22720","CVE-2022-22721","CVE-2022-23943","CVE-2022-26377","CVE-2022-28614","CVE-2022-28615","CVE-2022-29404","CVE-2022-30522","CVE-2022-30556","CVE-2022-31813","CVE-2022-36760","CVE-2022-37436","CVE-2023-25690","CVE-2023-27522","CVE-2023-31122","CVE-2023-38709","CVE-2023-45802","CVE-2024-24795","CVE-2024-27316","CVE-2024-38473","CVE-2024-38474","CVE-2024-38475","CVE-2024-38476","CVE-2024-38477","CVE-2024-39573","CVE-2024-39884","CVE-2024-40725","CVE-2024-42516","CVE-2024-43204","CVE-2024-47252","CVE-2025-23048","CVE-2025-49630","CVE-2025-49812","CVE-2025-53020","CVE-2025-55753","CVE-2025-58098","CVE-2025-65082","CVE-2025-66200","CVE-2026-23918","CVE-2026-24072","CVE-2026-28780","CVE-2026-29167","CVE-2026-29168","CVE-2026-29169","CVE-2026-29170","CVE-2026-33006","CVE-2026-33007","CVE-2026-33523","CVE-2026-33857","CVE-2026-34032","CVE-2026-34059","CVE-2026-34355","CVE-2026-34356","CVE-2026-42535","CVE-2026-42536","CVE-2026-43951","CVE-2026-44119","CVE-2026-44185","CVE-2026-44186","CVE-2026-44631","CVE-2026-48913","CVE-2026-49975"],"upstream":["CVE-2006-20001","CVE-2021-44224","CVE-2021-44790","CVE-2022-22719","CVE-2022-22720","CVE-2022-22721","CVE-2022-23943","CVE-2022-26377","CVE-2022-28614","CVE-2022-28615","CVE-2022-29404","CVE-2022-30522","CVE-2022-30556","CVE-2022-31813","CVE-2022-36760","CVE-2022-37436","CVE-2023-25690","CVE-2023-27522","CVE-2023-31122","CVE-2023-38709","CVE-2023-45802","CVE-2024-24795","CVE-2024-27316","CVE-2024-38473","CVE-2024-38474","CVE-2024-38475","CVE-2024-38476","CVE-2024-38477","CVE-2024-39573","CVE-2024-39884","CVE-2024-40725","CVE-2024-42516","CVE-2024-43204","CVE-2024-47252","CVE-2025-23048","CVE-2025-49630","CVE-2025-49812","CVE-2025-53020","CVE-2025-55753","CVE-2025-58098","CVE-2025-65082","CVE-2025-66200","CVE-2026-23918","CVE-2026-24072","CVE-2026-28780","CVE-2026-29167","CVE-2026-29168","CVE-2026-29169","CVE-2026-29170","CVE-2026-33006","CVE-2026-33007","CVE-2026-33523","CVE-2026-33857","CVE-2026-34032","CVE-2026-34059","CVE-2026-34355","CVE-2026-34356","CVE-2026-42535","CVE-2026-42536","CVE-2026-43951","CVE-2026-44119","CVE-2026-44185","CVE-2026-44186","CVE-2026-44631","CVE-2026-48913","CVE-2026-49975"],"summary":"Security update for apache2","details":"This update for apache2 fixes the following issues\n\n- CVE-2026-23918: http2: double free and possible RCE on early reset (bsc#1263957).\n- CVE-2026-24072: mod_rewrite elevation of privileges via ap_expr (bsc#1263935).\n- CVE-2026-28780: heap buffer overflow in `mod_proxy_ajp` via `ajp_msg_check_header()` (bsc#1264163).\n- CVE-2026-29167: mod_ldap per-dir use-after-free (bsc#1267976).\n- CVE-2026-29168: allocation of resources without limits in `mod_md` via OCSP response (bsc#1264150).\n- CVE-2026-29169: NULL pointer dereference in `mod_dav_lock` allows server crash via malicious requests (bsc#1263956).\n- CVE-2026-29170: mod_proxy_ftp XSS (bsc#1267977).\n- CVE-2026-33006: `mod_auth_digest` timing attack allows bypass of Digest authentication (bsc#1263955).\n- CVE-2026-33007: NULL pointer dereference in `mod_authn_socache` allows unauthenticated remote user to crash a child\n  processes (bsc#1263954).\n- CVE-2026-33523: HTTP response splitting forwarding malicious status line (bsc#1263953).\n- CVE-2026-33857: off-by-one OOB reads in AJP getter functions (bsc#1263952).\n- CVE-2026-34032: heap buffer overread in `mod_proxy_ajp` due to missing null-termination check (bsc#1263951).\n- CVE-2026-34059: heap buffer overread and memory disclosure via `ajp_parse_data()` (bsc#1263950).\n- CVE-2026-34355: mod_proxy_html buffer overflow (bsc#1267978).\n- CVE-2026-34356: malicious backend servers can lead to a heap-based buffer overflow (bsc#1267955).\n- CVE-2026-42535: malicious path manipulation can lead to child process crashes (bsc#1267956).\n- CVE-2026-42536: processing untrusted content can lead to a heap-based buffer overflow (bsc#1267962).\n- CVE-2026-43951: out-of-bound read in `merge_response_headers` can cause crash (bsc#1267963).\n- CVE-2026-44119: improper privilege management can lead to an unauthorized read (bsc#1267965).\n- CVE-2026-44185: Stack Buffer Over-Read in mod_ssl OCSP `send_request` (bsc#1267969).\n- CVE-2026-44186: responses from an attacker-controlled FTP backend can lead to resource exhaustion and a denial of\n  service (bsc#1267970).\n- CVE-2026-44631: crafted regular expression can lead to a buffer underwrite (bsc#1267971).\n- CVE-2026-48913: file handle exhaustion during request processing in mod_http2 can lead to a use-after-free\n  (bsc#1267972).\n- CVE-2026-49975: Fix cookie header accounting against LimitRequestFields (bsc#1267503).\n\nNon security issue:\n\n- Update to 2.4.66 (jsc#PED-16334).\n","affected":[{"package":{"name":"apache2","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS","purl":"pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.66-150400.6.57.1"}]}],"ecosystem_specific":{"binaries":[{"apache2":"2.4.66-150400.6.57.1","apache2-devel":"2.4.66-150400.6.57.1","apache2-doc":"2.4.66-150400.6.57.1","apache2-prefork":"2.4.66-150400.6.57.1","apache2-utils":"2.4.66-150400.6.57.1","apache2-worker":"2.4.66-150400.6.57.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2686-1.json"}},{"package":{"name":"apache2","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS","purl":"pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.66-150400.6.57.1"}]}],"ecosystem_specific":{"binaries":[{"apache2":"2.4.66-150400.6.57.1","apache2-devel":"2.4.66-150400.6.57.1","apache2-doc":"2.4.66-150400.6.57.1","apache2-prefork":"2.4.66-150400.6.57.1","apache2-utils":"2.4.66-150400.6.57.1","apache2-worker":"2.4.66-150400.6.57.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2686-1.json"}},{"package":{"name":"apache2","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS","purl":"pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.66-150400.6.57.1"}]}],"ecosystem_specific":{"binaries":[{"apache2":"2.4.66-150400.6.57.1","apache2-devel":"2.4.66-150400.6.57.1","apache2-doc":"2.4.66-150400.6.57.1","apache2-prefork":"2.4.66-150400.6.57.1","apache2-utils":"2.4.66-150400.6.57.1","apache2-worker":"2.4.66-150400.6.57.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2686-1.json"}},{"package":{"name":"apache2","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS","purl":"pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.66-150400.6.57.1"}]}],"ecosystem_specific":{"binaries":[{"apache2":"2.4.66-150400.6.57.1","apache2-devel":"2.4.66-150400.6.57.1","apache2-doc":"2.4.66-150400.6.57.1","apache2-prefork":"2.4.66-150400.6.57.1","apache2-utils":"2.4.66-150400.6.57.1","apache2-worker":"2.4.66-150400.6.57.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2686-1.json"}},{"package":{"name":"apache2","ecosystem":"SUSE:Linux Enterprise Server 15 SP4-LTSS","purl":"pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.66-150400.6.57.1"}]}],"ecosystem_specific":{"binaries":[{"apache2":"2.4.66-150400.6.57.1","apache2-devel":"2.4.66-150400.6.57.1","apache2-doc":"2.4.66-150400.6.57.1","apache2-prefork":"2.4.66-150400.6.57.1","apache2-utils":"2.4.66-150400.6.57.1","apache2-worker":"2.4.66-150400.6.57.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2686-1.json"}},{"package":{"name":"apache2","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.66-150400.6.57.1"}]}],"ecosystem_specific":{"binaries":[{"apache2":"2.4.66-150400.6.57.1","apache2-devel":"2.4.66-150400.6.57.1","apache2-doc":"2.4.66-150400.6.57.1","apache2-prefork":"2.4.66-150400.6.57.1","apache2-utils":"2.4.66-150400.6.57.1","apache2-worker":"2.4.66-150400.6.57.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2686-1.json"}},{"package":{"name":"apache2","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP4","purl":"pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.66-150400.6.57.1"}]}],"ecosystem_specific":{"binaries":[{"apache2":"2.4.66-150400.6.57.1","apache2-devel":"2.4.66-150400.6.57.1","apache2-doc":"2.4.66-150400.6.57.1","apache2-prefork":"2.4.66-150400.6.57.1","apache2-utils":"2.4.66-150400.6.57.1","apache2-worker":"2.4.66-150400.6.57.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2686-1.json"}},{"package":{"name":"apache2","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.66-150400.6.57.1"}]}],"ecosystem_specific":{"binaries":[{"apache2":"2.4.66-150400.6.57.1","apache2-devel":"2.4.66-150400.6.57.1","apache2-doc":"2.4.66-150400.6.57.1","apache2-prefork":"2.4.66-150400.6.57.1","apache2-utils":"2.4.66-150400.6.57.1","apache2-worker":"2.4.66-150400.6.57.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2686-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262686-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1207327"},{"type":"REPORT","url":"https://bugzilla.suse.com/1208708"},{"type":"REPORT","url":"https://bugzilla.suse.com/1214357"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263935"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263950"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263951"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263952"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263953"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263954"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263955"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263956"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263957"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264150"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264163"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267503"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267955"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267956"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267962"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267963"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267965"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267969"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267970"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267971"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267972"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267976"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267977"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267978"},{"type":"REPORT","url":"https://bugzilla.suse.com/690734"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2006-20001"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-44224"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-44790"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-22719"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-22720"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-22721"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-23943"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-26377"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-28614"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-28615"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-29404"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-30522"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-30556"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-31813"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-36760"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-37436"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-25690"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-27522"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-31122"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-38709"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-45802"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-24795"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-27316"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-38473"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-38474"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-38475"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-38476"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-38477"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-39573"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-39884"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-40725"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-42516"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-43204"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-47252"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-23048"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-49630"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-49812"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-53020"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-55753"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-58098"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-65082"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-66200"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23918"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-24072"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28780"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-29167"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-29168"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-29169"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-29170"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33006"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33007"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33523"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33857"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34032"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34059"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34355"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34356"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42535"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42536"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43951"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44119"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44185"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44186"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44631"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48913"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-49975"}]}