Apache HTTP Server on Linux: which version fixes what
Apache ships with dozens of modules and most installations need four of them. The advisory list is long partly because the software is old and popular, and partly because a default install enables things nobody asked for.
SecAI tracks 246 distinct CVEs affecting Apache HTTP Server across the 6 distributions below, of which 8 have no fixed package version on at least one of them. Each row names the package version that fixes it on that release.
What it is, and why it is on your server
The Apache HTTP Server, packaged as apache2 on Debian and Ubuntu and httpd on Rocky and AlmaLinux, is still the web server behind an enormous number of hosting panels, and it is what cPanel and Plesk configure by default.
Why its advisories behave the way they do
- Most Apache advisories are module-specific. mod_proxy, mod_rewrite and mod_http2 account for a large share of them, and if the module is not enabled the advisory does not apply to you. Knowing which are loaded is the difference between a real finding and noise.
- Two names, two lives. The same CVE arrives as apache2 on Debian and httpd on Rocky, on different dates, with completely different version strings. Searching one name finds half the picture.
- Hosting panels re-enable things. A panel that rewrites the configuration on update can quietly switch a module back on, which is why a server can become exposed to an old advisory without anybody installing anything.
Check what you are actually running
The version that matters is the package version, not the upstream one. Distributions backport security fixes without changing the number before the dash, so a release that looks years old is frequently fully patched, and the revision after the dash is the only part that tells you.
dpkg-query -W -f='${Package} ${Version}\n' apache2 apache2-bin 2>/dev/nullrpm -q httpd httpd-coreRun `apache2ctl -M` on Debian and Ubuntu, or `httpd -M` on Rocky and AlmaLinux, to list the modules actually loaded.
Fixed versions, per distribution
Each distribution patches on its own schedule and under its own version scheme, so the same CVE has a different answer on each of them. These come from the distributions’ own advisory data, asked per release. Where a release has no fixed version, that is what the advisory says, not a gap in the data.
Ubuntu 22.04 LTSsource package: apache2
| CVE | Published | Fixed in package version |
|---|---|---|
| CVE-2026-29167 | 2026-07-08 | 2.4.52-1ubuntu4.23 |
| CVE-2026-29170 | 2026-07-08 | 2.4.52-1ubuntu4.23 |
| CVE-2026-34355 | 2026-07-08 | 2.4.52-1ubuntu4.23 |
| CVE-2026-34356 | 2026-07-08 | 2.4.52-1ubuntu4.23 |
| CVE-2026-42535 | 2026-07-08 | 2.4.52-1ubuntu4.23 |
| CVE-2026-42536 | 2026-07-08 | 2.4.52-1ubuntu4.23 |
| CVE-2026-43951 | 2026-07-08 | 2.4.52-1ubuntu4.23 |
| CVE-2026-44119 | 2026-07-08 | 2.4.52-1ubuntu4.23 |
| CVE-2026-44185 | 2026-07-08 | 2.4.52-1ubuntu4.23 |
| CVE-2026-44186 | 2026-07-08 | 2.4.52-1ubuntu4.23 |
| CVE-2026-44631 | 2026-07-08 | 2.4.52-1ubuntu4.23 |
| CVE-2026-48913 | 2026-07-08 | 2.4.52-1ubuntu4.23 |
| CVE-2026-49975 | 2026-06-03 | 2.4.52-1ubuntu4.21 |
| CVE-2026-24072 | 2026-05-05 | 2.4.52-1ubuntu4.20 |
| CVE-2026-28780 | 2026-05-05 | 2.4.52-1ubuntu4.20 |
| CVE-2026-29168 | 2026-05-05 | 2.4.52-1ubuntu4.20 |
| CVE-2026-29169 | 2026-05-05 | 2.4.52-1ubuntu4.20 |
| CVE-2026-33006 | 2026-05-05 | 2.4.52-1ubuntu4.20 |
| CVE-2026-33007 | 2026-05-05 | 2.4.52-1ubuntu4.20 |
| CVE-2026-33523 | 2026-05-05 | 2.4.52-1ubuntu4.20 |
| CVE-2026-33857 | 2026-05-05 | 2.4.52-1ubuntu4.20 |
| CVE-2026-34032 | 2026-05-05 | 2.4.52-1ubuntu4.20 |
| CVE-2026-34059 | 2026-05-05 | 2.4.52-1ubuntu4.20 |
| CVE-2025-55753 | 2026-01-19 | 2.4.52-1ubuntu4.18 |
| CVE-2025-58098 | 2026-01-19 | 2.4.52-1ubuntu4.18 |
Showing the 25 most recent of 67 that apply to Ubuntu 22.04 LTS.
Ubuntu 24.04 LTSsource package: apache2
| CVE | Published | Fixed in package version |
|---|---|---|
| CVE-2026-29167 | 2026-07-08 | 2.4.58-1ubuntu8.15 |
| CVE-2026-29170 | 2026-07-08 | 2.4.58-1ubuntu8.15 |
| CVE-2026-34355 | 2026-07-08 | 2.4.58-1ubuntu8.15 |
| CVE-2026-34356 | 2026-07-08 | 2.4.58-1ubuntu8.15 |
| CVE-2026-42535 | 2026-07-08 | 2.4.58-1ubuntu8.15 |
| CVE-2026-42536 | 2026-07-08 | 2.4.58-1ubuntu8.15 |
| CVE-2026-43951 | 2026-07-08 | 2.4.58-1ubuntu8.15 |
| CVE-2026-44119 | 2026-07-08 | 2.4.58-1ubuntu8.15 |
| CVE-2026-44185 | 2026-07-08 | 2.4.58-1ubuntu8.15 |
| CVE-2026-44186 | 2026-07-08 | 2.4.58-1ubuntu8.15 |
| CVE-2026-44631 | 2026-07-08 | 2.4.58-1ubuntu8.15 |
| CVE-2026-48913 | 2026-07-08 | 2.4.58-1ubuntu8.15 |
| CVE-2026-49975 | 2026-06-03 | 2.4.58-1ubuntu8.13 |
| CVE-2026-24072 | 2026-05-05 | 2.4.58-1ubuntu8.12 |
| CVE-2026-28780 | 2026-05-05 | 2.4.58-1ubuntu8.12 |
| CVE-2026-29168 | 2026-05-05 | 2.4.58-1ubuntu8.12 |
| CVE-2026-29169 | 2026-05-05 | 2.4.58-1ubuntu8.12 |
| CVE-2026-33006 | 2026-05-05 | 2.4.58-1ubuntu8.12 |
| CVE-2026-33007 | 2026-05-05 | 2.4.58-1ubuntu8.12 |
| CVE-2026-33523 | 2026-05-05 | 2.4.58-1ubuntu8.12 |
| CVE-2026-33857 | 2026-05-05 | 2.4.58-1ubuntu8.12 |
| CVE-2026-34032 | 2026-05-05 | 2.4.58-1ubuntu8.12 |
| CVE-2026-34059 | 2026-05-05 | 2.4.58-1ubuntu8.12 |
| CVE-2025-55753 | 2026-01-19 | 2.4.58-1ubuntu8.10 |
| CVE-2025-58098 | 2026-01-19 | 2.4.58-1ubuntu8.10 |
Showing the 25 most recent of 47 that apply to Ubuntu 24.04 LTS.
Debian 12 (bookworm)source package: apache2
| CVE | Published | Fixed in package version |
|---|---|---|
| CVE-2026-29167 | 2026-06-08 | 2.4.68-1~deb12u1 |
| CVE-2026-29170 | 2026-06-08 | 2.4.68-1~deb12u1 |
| CVE-2026-34355 | 2026-06-08 | 2.4.68-1~deb12u1 |
| CVE-2026-34356 | 2026-06-08 | 2.4.68-1~deb12u1 |
| CVE-2026-42535 | 2026-06-08 | 2.4.68-1~deb12u1 |
| CVE-2026-42536 | 2026-06-08 | 2.4.68-1~deb12u1 |
| CVE-2026-43951 | 2026-06-08 | 2.4.68-1~deb12u1 |
| CVE-2026-44119 | 2026-06-08 | 2.4.68-1~deb12u1 |
| CVE-2026-44185 | 2026-06-08 | 2.4.68-1~deb12u1 |
| CVE-2026-44186 | 2026-06-08 | 2.4.68-1~deb12u1 |
| CVE-2026-44631 | 2026-06-08 | 2.4.68-1~deb12u1 |
| CVE-2026-48913 | 2026-06-08 | 2.4.68-1~deb12u1 |
| CVE-2026-49975 | 2026-06-08 | 2.4.67-1~deb12u3 |
| CVE-2026-28780 | 2026-05-05 | 2.4.67-1~deb12u2 |
| CVE-2026-29168 | 2026-05-05 | 2.4.67-1~deb12u2 |
| CVE-2026-23918 | 2026-05-04 | 2.4.67-1~deb12u2 |
| CVE-2026-24072 | 2026-05-04 | 2.4.67-1~deb12u2 |
| CVE-2026-29169 | 2026-05-04 | 2.4.67-1~deb12u2 |
| CVE-2026-33006 | 2026-05-04 | 2.4.67-1~deb12u2 |
| CVE-2026-33007 | 2026-05-04 | 2.4.67-1~deb12u2 |
| CVE-2026-33523 | 2026-05-04 | 2.4.67-1~deb12u2 |
| CVE-2026-33857 | 2026-05-04 | 2.4.67-1~deb12u2 |
| CVE-2026-34032 | 2026-05-04 | 2.4.67-1~deb12u2 |
| CVE-2026-34059 | 2026-05-04 | 2.4.67-1~deb12u2 |
| CVE-2025-55753 | 2025-12-05 | 2.4.66-1~deb12u1 |
Showing the 25 most recent of 244 that apply to Debian 12 (bookworm), 8 of which have no fixed version released.
Debian 13 (trixie)source package: apache2
| CVE | Published | Fixed in package version |
|---|---|---|
| CVE-2026-29167 | 2026-06-08 | 2.4.68-1~deb13u1 |
| CVE-2026-29170 | 2026-06-08 | 2.4.68-1~deb13u1 |
| CVE-2026-34355 | 2026-06-08 | 2.4.68-1~deb13u1 |
| CVE-2026-34356 | 2026-06-08 | 2.4.68-1~deb13u1 |
| CVE-2026-42535 | 2026-06-08 | 2.4.68-1~deb13u1 |
| CVE-2026-42536 | 2026-06-08 | 2.4.68-1~deb13u1 |
| CVE-2026-43951 | 2026-06-08 | 2.4.68-1~deb13u1 |
| CVE-2026-44119 | 2026-06-08 | 2.4.68-1~deb13u1 |
| CVE-2026-44185 | 2026-06-08 | 2.4.68-1~deb13u1 |
| CVE-2026-44186 | 2026-06-08 | 2.4.68-1~deb13u1 |
| CVE-2026-44631 | 2026-06-08 | 2.4.68-1~deb13u1 |
| CVE-2026-48913 | 2026-06-08 | 2.4.68-1~deb13u1 |
| CVE-2026-49975 | 2026-06-08 | 2.4.67-1~deb13u3 |
| CVE-2026-28780 | 2026-05-05 | 2.4.67-1~deb13u2 |
| CVE-2026-29168 | 2026-05-05 | 2.4.67-1~deb13u2 |
| CVE-2026-23918 | 2026-05-04 | 2.4.66-1~deb13u2 |
| CVE-2026-24072 | 2026-05-04 | 2.4.67-1~deb13u2 |
| CVE-2026-29169 | 2026-05-04 | 2.4.67-1~deb13u2 |
| CVE-2026-33006 | 2026-05-04 | 2.4.67-1~deb13u2 |
| CVE-2026-33007 | 2026-05-04 | 2.4.67-1~deb13u2 |
| CVE-2026-33523 | 2026-05-04 | 2.4.67-1~deb13u2 |
| CVE-2026-33857 | 2026-05-04 | 2.4.67-1~deb13u2 |
| CVE-2026-34032 | 2026-05-04 | 2.4.67-1~deb13u2 |
| CVE-2026-34059 | 2026-05-04 | 2.4.67-1~deb13u2 |
| CVE-2025-55753 | 2025-12-05 | 2.4.66-1~deb13u1 |
Showing the 25 most recent of 246 that apply to Debian 13 (trixie), 8 of which have no fixed version released.
Rocky Linux 9source package: httpd
| CVE | Published | Fixed in package version |
|---|---|---|
| CVE-2026-29167 | 2026-08-26 | 0:2.4.62-13.el9_8.6 |
| CVE-2024-42516 | 2026-07-22 | 0:2.4.62-13.el9_8.5 |
| CVE-2026-24072 | 2026-07-22 | 0:2.4.62-13.el9_8.5 |
| CVE-2026-29169 | 2026-07-22 | 0:2.4.62-13.el9_8.5 |
| CVE-2026-33006 | 2026-07-22 | 0:2.4.62-13.el9_8.5 |
| CVE-2026-34355 | 2026-07-22 | 0:2.4.62-13.el9_8.5 |
| CVE-2026-34356 | 2026-07-22 | 0:2.4.62-13.el9_8.5 |
| CVE-2026-42535 | 2026-07-22 | 0:2.4.62-13.el9_8.5 |
| CVE-2026-42536 | 2026-07-22 | 0:2.4.62-13.el9_8.5 |
| CVE-2026-43951 | 2026-07-22 | 0:2.4.62-13.el9_8.5 |
| CVE-2026-44119 | 2026-07-22 | 0:2.4.62-13.el9_8.5 |
| CVE-2026-44185 | 2026-07-22 | 0:2.4.62-13.el9_8.5 |
| CVE-2026-44186 | 2026-07-22 | 0:2.4.62-13.el9_8.5 |
| CVE-2026-44631 | 2026-07-22 | 0:2.4.62-13.el9_8.5 |
| CVE-2026-28780 | 2026-05-30 | 0:2.4.62-13.el9_8.1 |
| CVE-2026-33007 | 2026-05-30 | 0:2.4.62-13.el9_8.1 |
| CVE-2026-33857 | 2026-05-30 | 0:2.4.62-13.el9_8.1 |
| CVE-2026-34032 | 2026-05-30 | 0:2.4.62-13.el9_8.1 |
| CVE-2026-34059 | 2026-05-30 | 0:2.4.62-13.el9_8.1 |
| CVE-2025-58098 | 2025-12-23 | 0:2.4.62-7.el9_7.3 |
| CVE-2025-65082 | 2025-12-23 | 0:2.4.62-7.el9_7.3 |
| CVE-2025-66200 | 2025-12-23 | 0:2.4.62-7.el9_7.3 |
| CVE-2024-47252 | 2025-10-10 | 0:2.4.62-4.el9_6.4 |
| CVE-2025-23048 | 2025-10-10 | 0:2.4.62-4.el9_6.4 |
| CVE-2025-49812 | 2025-10-10 | 0:2.4.62-4.el9_6.4 |
Showing the 25 most recent of 48 that apply to Rocky Linux 9.
AlmaLinux 9source package: httpd
| CVE | Published | Fixed in package version |
|---|---|---|
| CVE-2026-29167 | 2026-08-25 | 2.4.62-13.el9_8.6 |
| CVE-2023-38709 | 2026-07-20 | 2.4.62-13.el9_8.5 |
| CVE-2024-42516 | 2026-07-20 | 2.4.62-13.el9_8.5 |
| CVE-2026-24072 | 2026-07-20 | 2.4.62-13.el9_8.5 |
| CVE-2026-29169 | 2026-07-20 | 2.4.62-13.el9_8.5 |
| CVE-2026-33006 | 2026-07-20 | 2.4.62-13.el9_8.5 |
| CVE-2026-34355 | 2026-07-20 | 2.4.62-13.el9_8.5 |
| CVE-2026-34356 | 2026-07-20 | 2.4.62-13.el9_8.5 |
| CVE-2026-42535 | 2026-07-20 | 2.4.62-13.el9_8.5 |
| CVE-2026-42536 | 2026-07-20 | 2.4.62-13.el9_8.5 |
| CVE-2026-43951 | 2026-07-20 | 2.4.62-13.el9_8.5 |
| CVE-2026-44119 | 2026-07-20 | 2.4.62-13.el9_8.5 |
| CVE-2026-44185 | 2026-07-20 | 2.4.62-13.el9_8.5 |
| CVE-2026-44186 | 2026-07-20 | 2.4.62-13.el9_8.5 |
| CVE-2026-44631 | 2026-07-20 | 2.4.62-13.el9_8.5 |
| CVE-2026-28780 | 2026-05-27 | 2.4.62-13.el9_8.1 |
| CVE-2026-33007 | 2026-05-27 | 2.4.62-13.el9_8.1 |
| CVE-2026-33857 | 2026-05-27 | 2.4.62-13.el9_8.1 |
| CVE-2026-34032 | 2026-05-27 | 2.4.62-13.el9_8.1 |
| CVE-2026-34059 | 2026-05-27 | 2.4.62-13.el9_8.1 |
| CVE-2025-58098 | 2025-12-22 | 2.4.62-7.el9_7.3 |
| CVE-2025-65082 | 2025-12-22 | 2.4.62-7.el9_7.3 |
| CVE-2025-66200 | 2025-12-22 | 2.4.62-7.el9_7.3 |
| CVE-2024-47252 | 2025-09-02 | 2.4.62-4.el9_6.4 |
| CVE-2025-23048 | 2025-09-02 | 2.4.62-4.el9_6.4 |
Showing the 25 most recent of 49 that apply to AlmaLinux 9.
Advisory data last refreshed 26 September 2026. It is re-read daily.
What this page does not tell you
It does not tell you whether your server is affected. A CVE applying to a package is not the same as a CVE applying to your installation: the fix may already be backported into what you are running, the vulnerable module may not be loaded, or the service may not be reachable from anywhere that matters. Answering that needs the versions on your machine, not a list.
It also carries no count of how many servers are affected. SecAI monitors a small fleet, and a percentage drawn from it would be arithmetic on a sample too small to mean anything. When that changes, the number will appear here and the page will say when it started.
Read next
Find out which of these you are running
One read-only command, no account, no agent. It reads the installed package versions on your server and tells you which advisories actually apply to them, Apache HTTP Server included. It changes nothing.