Path to this page:
./
www/apache24,
Apache HTTP (Web) server, version 2.4
Branch: CURRENT,
Version: 2.4.69,
Package name: apache-2.4.69,
Maintainer: ryoonThe Apache HTTP Server Project is an effort to develop and maintain an
open-source HTTP server for various modern desktop and server operating
systems, such as UNIX and Windows NT. The goal of this project is to
provide a secure, efficient and extensible server which provides HTTP
services in sync with the current HTTP standards.
This package tracks 2.4.x release.
Required to run:[
textproc/libxml2] [
security/openssl] [
devel/apr] [
devel/apr-util] [
devel/pcre] [
devel/readline] [
www/nghttp2] [
archivers/brotli]
Required to build:[
pkgtools/cwrappers]
Package options: apache-mpm-event, apache-mpm-prefork, apache-mpm-worker, brotli, http2, xml
Master sites:
Filesize: 8313.528 KB
Version history: (Expand)
- (2026-10-02) Updated to version: apache-2.4.69
- (2026-09-29) Updated to version: apache-2.4.68nb3
- (2026-09-27) Updated to version: apache-2.4.68nb2
- (2026-09-03) Package has been reborn
- (2026-09-03) Package deleted from pkgsrc
- (2026-09-02) Updated to version: apache-2.4.68nb1
CVS history: (Expand)
2026-10-02 02:54:11 by Takahiro Kambe | Files touched by this commit (3) |  |
Log message:
www/apache24: update to 2.4.69
Apache 2.4.69 (2026-10-01)
*) Fix the tar icon in the documentation so that its background is
transparent. #70238. [Jeffery To <jeffery.to gmail.com>]
*) mod_ssl: Fix OpenSSL compatibility macros for X509_get0_notBefore,
X509_get0_notAfter, and X509_get0_serialNumber with OpenSSL < 1.1.
#70205. [Craig Lorentzen <crlorent amazon.com>]
*) mod_cgid, mod_ssl, mod_md: Various hardening fixes. [Various authors]
*) mod_md: MDServerStatus is now disabled by default. [Joe Orton]
*) mod_auth_digest: Fix compatibility with expression-based AuthName.
#59039. [Eric Covener]
*) mod_auth_digest.c: Drop RFC 2069 support; rewrite shared memory
handling and client nonce handling; "authdigest-opaque" mutex is
now longer needed. [Joe Orton]
*) mod_lbmethod_heartbeat: Use safe integer parsing with range
validation, replacing atoi(). [Sayed Kaif <metsw24 gmail.com>]
*) core: Reject control characters in the reason phrase of interim
responses. Only accept space as status-code separator. [Joe Orton]
*) mod_substitute: Fix SubstituteMaxLineLength to reject values too
large for the K/M/G suffix. [Joe Orton]
*) mod_substitute: Fix crash or misbehaviour when loading a Substitute
directive with a missing closing delimiter. [Joe Orton]
*) mod_dir: Fix a crash in fixup_dir for a request not mapped to any type.
#68527. [Eric Covener]
*) mod_http2: Do not drop an in-flight response when a client sends a
graceful GOAWAY (error code 0) while streams it opened are still
being processed. The session now drains open streams instead of
tearing down immediately, which async MPMs hit far more than event.
Fixes a silently dropped response; RFC 9113 compliant. [Jim Jagielski]
*) mod_md: OpenSSL 4 compatibility.
*) pytest_suite: Port of the old PERL test framework to Python
and pytest. Now included in the source tree under ./test
[Jim Jagielski]
|
| 2026-09-29 08:08:46 by Thomas Klausner | Files touched by this commit (3127) |
Log message:
*: recursive bump for pcre2 10.49
|
| 2026-09-27 13:39:47 by Tobias Nygren | Files touched by this commit (3126) |
Log message:
*: revbump for pcre2 symbol versioning change
|
| 2026-09-02 21:05:38 by Thomas Klausner | Files touched by this commit (3127) |
Log message:
*: recursive bump for pcre2 10.48
|
2026-06-09 03:22:47 by Takahiro Kambe | Files touched by this commit (3) |  |
Log message:
www/apache24: update to 2.4.68
Apache 2.4.68 (2026-06-08)
Changes with Apache 2.4.68
*) mod_ssl, ab: Add support for OpenSSL 4.0. [Joe Orton]
*) mod_ssl: Add SerialNumber as a recognized attribute type for SSL
distinguished name variables. [Michael Osipov <michaelo apache.org>,
Benjamin Demarteau <benjamin.demarteau liege.be>]
*) mod_ssl: Set auth type to "ClientCert" when client certificate \
authentication
has been performed. [Michael Osipov <michaelo apache.org>]
*) mod_include: Don't print any of if/elsif/else content when
a conditional evaluation returns an error. [Eric Covener]
*) mod_unixd: CoreDumpDirectory requires enabling tracing on FreeBSD 11+.
PR 65819. [David CARLIER <devnexen gmail.com>]
*) mod_file_cache: Fix crashes for mmap'ed files under threaded
MPMs. PR 69901. barr.israel <barr.israel campus.technion.ac.il>
*) core: Add support for %{m}t in ErrorLogFormat to log milli-second
time resolution (in addition to existing %{u}t for micro-seconds).
[Luboš Uhliarik <luhliari redhat.com>]
*) mod_unixd: Drop test that effective user ID is zero in
a chroot configuration. PR 69767.
[Bastien Roucaries <rouca debian.org>]
*) mod_proxy_balancer: Include nonce in XML output. PR 63074.
Federico Mennite <federico.mennite lifeware.ch>
*) mod_http2: update to version 2.0.42
Fix excessive file description use for non-TLS frontend connections when
sending files. Fixes <https://github.com/icing/mod_h2/issues/325>
[Stefan Eissing]
*) mod_http2: update to version 2.0.41
Fix cookie header accounting against LimitRequestFields.
[Stefan Eissing]
*) mod_http2: update to version 2.0.40
Fix error handling on upload requests when server runs out of file
handles that left beam bucket callbacks in place, potentially using
no longer valid references. Only applies on platforms with pipes
and file descriptor limits not healthy for a network server.
[Stefan Eissing]
*) mod_dav_fs: Return a 404 for DELETE if deletion fails because the
resource no longer exists. PR 60746. [Joe Orton]
*) mod_proxy_hcheck: Fix healthcheck disabled due to child restart while
updating. [Yann Ylavic]
|
| 2026-05-14 18:42:34 by Ryo ONODERA | Files touched by this commit (1335) |
Log message:
*: Recursive revbump from security/nettle-4.0
|
2026-05-05 02:12:30 by Takahiro Kambe | Files touched by this commit (6) |  |
Log message:
www/apache24: update to 2.4.67
Changes with Apache 2.4.67 (2026-05-04)
* SECURITY: CVE-2026-34059: Apache HTTP Server: mod_proxy_ajp: Heap
Over-Read and memory disclosure in ajp_parse_data() (cve.mitre.org)
Buffer Over-read vulnerability in Apache HTTP Server. This issue affects
Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to
version 2.4.67, which fixes the issue. Credits: Elhanan Haenel
* SECURITY: CVE-2026-34032: Apache HTTP Server: mod_proxy_ajp: Heap Buffer
Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string)
(cve.mitre.org) Improper Null Termination, Out-of-bounds Read
vulnerability in Apache HTTP Server. This issue affects Apache HTTP
Server: through 2.4.66. Users are recommended to upgrade to version
2.4.67, which fixes the issue. Credits: Tianshuo Han
(<hantianshuo233@gmail.com>)
* SECURITY: CVE-2026-33857: Apache HTTP Server: Off-by-one OOB reads in AJP
getter functions (cve.mitre.org) Out-of-bounds Read vulnerability in
mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP
Server: through 2.4.66. Users are recommended to upgrade to version
2.4.67, which fixes the issue. Credits: Elhanan Haenel
* SECURITY: CVE-2026-33523: Apache HTTP Server: multiple modules: HTTP
response splitting forwarding malicious status line (cve.mitre.org) HTTP
response splitting vulnerability in multiple Apache HTTP Server modules
with untrusted or compromised backend servers. This issue affects Apache
HTTP Server: from through 2.4.66. Users are recommended to upgrade to
version 2.4.67, which fixes the issue. Credits: Haruki Oyama (Waseda
University)
* SECURITY: CVE-2026-33007: Apache HTTP Server: mod_authn_socache crash
(cve.mitre.org) A NULL pointer dereference in the mod_authn_socache in
Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote
user to crash a child process in a caching forward proxy configuration.
Users are recommended to upgrade to version 2.4.67, which fixes this
issue. Credits: Pavel Kohout, Aisle Research, Aisle.com
* SECURITY: CVE-2026-33006: Apache HTTP Server: mod_auth_digest timing
attack (cve.mitre.org) A timing attack against mod_auth_digest in Apache
HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote
attacker. Users are recommended to upgrade to version 2.4.67, which fixes
this issue. Credits: Nitescu Lucian
* SECURITY: CVE-2026-29169: Apache HTTP Server: mod_dav_lock indirect lock
crash (cve.mitre.org) A NULL pointer dereference in mod_dav_lock in Apache
HTTP Server 2.4.66 and earlier may allow an attacker to crash the server
with a malicious request.mod_dav_lock is not used internally by mod_dav or
mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from
Apache Subversion earlier than version 1.2.0. Users are recommended to
upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.
Credits: Pavel Kohout, Aisle Research, Aisle.com
* SECURITY: CVE-2026-29168: Apache HTTP Server: mod_md unrestricted OCSP
response (cve.mitre.org) Allocation of Resources Without Limits or
Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response
data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Credits: Pavel Kohout, Aisle Research, Aisle.com
* SECURITY: CVE-2026-28780: Apache HTTP Server: buffer overflow in
mod_proxy_ajp via ajp_msg_check_header() (cve.mitre.org) Heap-based Buffer
Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If
mod_proxy_ajp connects to a malicious AJP server this AJP server can send
a malicious AJP message back to mod_proxy_ajp and cause it to write 4
attacker controlled bytes after the end of a heap based buffer. This
issue affects Apache HTTP Server: through 2.4.66. Users are recommended
to upgrade to version 2.4.67, which fixes the issue. Credits: Andrew
Lacambra
* SECURITY: CVE-2026-24072: Apache HTTP Server: mod_rewrite elevation of
privileges via ap_expr (cve.mitre.org) An escalation of privilege bug in
various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess
authors to read files with the privileges of the httpd user. Users are
recommended to upgrade to version 2.4.67, which fixes this issue.
Credits: y7syeu
* SECURITY: CVE-2026-23918: Apache HTTP Server: http2: double free and
possible RCE on early reset (cve.mitre.org) Double Free and possible RCE
vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue
affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to
version 2.4.67, which fixes the issue. Credits: Bartlomiej Dmitruk,
striga.ai
* mod_md: update to version 2.6.10
- Fix issue #420 <https://github.com/icing/mod_md/issues/420> by ignoring
job.json files that claim to have completely finished a certificate
renewal, but have not produced the necessary result files.
* mod_http2: update to version 2.0.39
Remove streams own memory allocator after reports of memory problems with
third party modules. [Stefan Eissing]
* mod_http2: update to version 2.0.38
Source sync with mod_h2 github repository. No functional change. [Stefan
Eissing]
* Updated conf/mime.types: added vnd.sqlite3, HEIC, HEIF
[Alexandru Mărășteanu <hello alexei.ro>]
* mod_md: update to version 2.6.7
- Fix a regression in `MDStapleOthers` which broke in v2.6.0 and no longer
applied, no matter the configuration.
* mod_md: update to version 2.6.9
- Pebble 2.9+ reports another error when terms of service agreement is not
set. Treating all "userActionRequired" errors as permanent now.
* mod_md: update to version 2.6.8
- Fix the ARI related `replaces` property in ACME order creation to only
be used when the CA supports ARI and it is enabled in the menu config.
- Fix compatibility with APR versions before 1.6.0 which do not have
`apr_cstr_casecmp` and should use `apr_strnatcasecmp` instead.
* mod_http2: update to version 2.0.37
Prevent double purge of a stream, resulting in a double free. Fixes PR
69899. [Stefan Eissing]
* mod_md: Use correct function name when compiling against APR < 1.6.0.
PR 69954 [Tần Quảng <baobaoxich@gmail.com>]
|
| 2026-02-06 11:06:21 by Thomas Klausner | Files touched by this commit (1305) |
Log message:
*: recursive bump for nettle 4.0 shlib major bump
|