./www/apache24, Apache HTTP (Web) server, version 2.4

[ Image CVSweb ] [ Image Homepage ] [ Image RSS ] [ Image Required by ]


Branch: CURRENT, Version: 2.4.69, Package name: apache-2.4.69, Maintainer: ryoon

The Apache HTTP Server Project is an effort to develop and maintain an
open-source HTTP server for various modern desktop and server operating
systems, such as UNIX and Windows NT. The goal of this project is to
provide a secure, efficient and extensible server which provides HTTP
services in sync with the current HTTP standards.

This package tracks 2.4.x release.


Required to run:
[textproc/libxml2] [security/openssl] [devel/apr] [devel/apr-util] [devel/pcre] [devel/readline] [www/nghttp2] [archivers/brotli]

Required to build:
[pkgtools/cwrappers]

Package options: apache-mpm-event, apache-mpm-prefork, apache-mpm-worker, brotli, http2, xml

Master sites:

Filesize: 8313.528 KB

Version history: (Expand)


CVS history: (Expand)


   2026-10-02 02:54:11 by Takahiro Kambe | Files touched by this commit (3) | Package updated
Log message:
www/apache24: update to 2.4.69

Apache 2.4.69 (2026-10-01)

  *) Fix the tar icon in the documentation so that its background is
     transparent.  #70238.  [Jeffery To <jeffery.to gmail.com>]

  *) mod_ssl: Fix OpenSSL compatibility macros for X509_get0_notBefore,
     X509_get0_notAfter, and X509_get0_serialNumber with OpenSSL < 1.1.
     #70205.  [Craig Lorentzen <crlorent amazon.com>]

  *) mod_cgid, mod_ssl, mod_md: Various hardening fixes.  [Various authors]

  *) mod_md: MDServerStatus is now disabled by default.  [Joe Orton]

  *) mod_auth_digest: Fix compatibility with expression-based AuthName.
     #59039.  [Eric Covener]

  *) mod_auth_digest.c: Drop RFC 2069 support; rewrite shared memory
     handling and client nonce handling; "authdigest-opaque" mutex is
     now longer needed.  [Joe Orton]

  *) mod_lbmethod_heartbeat: Use safe integer parsing with range
     validation, replacing atoi().  [Sayed Kaif <metsw24 gmail.com>]

  *) core: Reject control characters in the reason phrase of interim
     responses.  Only accept space as status-code separator.  [Joe Orton]

  *) mod_substitute: Fix SubstituteMaxLineLength to reject values too
     large for the K/M/G suffix.  [Joe Orton]

  *) mod_substitute: Fix crash or misbehaviour when loading a Substitute
     directive with a missing closing delimiter.  [Joe Orton]

  *) mod_dir: Fix a crash in fixup_dir for a request not mapped to any type.
     #68527.  [Eric Covener]

  *) mod_http2: Do not drop an in-flight response when a client sends a
     graceful GOAWAY (error code 0) while streams it opened are still
     being processed. The session now drains open streams instead of
     tearing down immediately, which async MPMs hit far more than event.
     Fixes a silently dropped response; RFC 9113 compliant. [Jim Jagielski]

  *) mod_md: OpenSSL 4 compatibility.

  *) pytest_suite: Port of the old PERL test framework to Python
     and pytest. Now included in the source tree under ./test
     [Jim Jagielski]
   2026-09-29 08:08:46 by Thomas Klausner | Files touched by this commit (3127)
Log message:
*: recursive bump for pcre2 10.49
   2026-09-27 13:39:47 by Tobias Nygren | Files touched by this commit (3126)
Log message:
*: revbump for pcre2 symbol versioning change
   2026-09-02 21:05:38 by Thomas Klausner | Files touched by this commit (3127)
Log message:
*: recursive bump for pcre2 10.48
   2026-06-09 03:22:47 by Takahiro Kambe | Files touched by this commit (3) | Package updated
Log message:
www/apache24: update to 2.4.68

Apache 2.4.68 (2026-06-08)

Changes with Apache 2.4.68

  *) mod_ssl, ab: Add support for OpenSSL 4.0.  [Joe Orton]

  *) mod_ssl: Add SerialNumber as a recognized attribute type for SSL
     distinguished name variables.  [Michael Osipov <michaelo apache.org>,
     Benjamin Demarteau <benjamin.demarteau liege.be>]

  *) mod_ssl: Set auth type to "ClientCert" when client certificate \ 
authentication
     has been performed.  [Michael Osipov <michaelo apache.org>]

  *) mod_include: Don't print any of if/elsif/else content when
     a conditional evaluation returns an error. [Eric Covener]

  *) mod_unixd: CoreDumpDirectory requires enabling tracing on FreeBSD 11+.
     PR 65819.  [David CARLIER <devnexen gmail.com>]

  *) mod_file_cache: Fix crashes for mmap'ed files under threaded
     MPMs. PR 69901. barr.israel <barr.israel campus.technion.ac.il>

  *) core: Add support for %{m}t in ErrorLogFormat to log milli-second
     time resolution (in addition to existing %{u}t for micro-seconds).
     [Luboš Uhliarik <luhliari redhat.com>]

  *) mod_unixd: Drop test that effective user ID is zero in
     a chroot configuration.  PR 69767.
     [Bastien Roucaries <rouca debian.org>]

  *) mod_proxy_balancer: Include nonce in XML output.  PR 63074.
     Federico Mennite <federico.mennite lifeware.ch>

  *) mod_http2: update to version 2.0.42
     Fix excessive file description use for non-TLS frontend connections when
     sending files. Fixes <https://github.com/icing/mod_h2/issues/325>
     [Stefan Eissing]

  *) mod_http2: update to version 2.0.41
     Fix cookie header accounting against LimitRequestFields.
     [Stefan Eissing]

  *) mod_http2: update to version 2.0.40
     Fix error handling on upload requests when server runs out of file
     handles that left beam bucket callbacks in place, potentially using
     no longer valid references. Only applies on platforms with pipes
     and file descriptor limits not healthy for a network server.
     [Stefan Eissing]

  *) mod_dav_fs: Return a 404 for DELETE if deletion fails because the
     resource no longer exists.  PR 60746.  [Joe Orton]

  *) mod_proxy_hcheck: Fix healthcheck disabled due to child restart while
     updating. [Yann Ylavic]
   2026-05-14 18:42:34 by Ryo ONODERA | Files touched by this commit (1335)
Log message:
*: Recursive revbump from security/nettle-4.0
   2026-05-05 02:12:30 by Takahiro Kambe | Files touched by this commit (6) | Package updated
Log message:
www/apache24: update to 2.4.67

Changes with Apache 2.4.67 (2026-05-04)

* SECURITY: CVE-2026-34059: Apache HTTP Server: mod_proxy_ajp: Heap
  Over-Read and memory disclosure in ajp_parse_data() (cve.mitre.org)
  Buffer Over-read vulnerability in Apache HTTP Server.  This issue affects
  Apache HTTP Server: through 2.4.66.  Users are recommended to upgrade to
  version 2.4.67, which fixes the issue.  Credits: Elhanan Haenel

* SECURITY: CVE-2026-34032: Apache HTTP Server: mod_proxy_ajp: Heap Buffer
  Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string)
  (cve.mitre.org) Improper Null Termination, Out-of-bounds Read
  vulnerability in Apache HTTP Server.  This issue affects Apache HTTP
  Server: through 2.4.66.  Users are recommended to upgrade to version
  2.4.67, which fixes the issue.  Credits: Tianshuo Han
  (<hantianshuo233@gmail.com>)

* SECURITY: CVE-2026-33857: Apache HTTP Server: Off-by-one OOB reads in AJP
  getter functions (cve.mitre.org) Out-of-bounds Read vulnerability in
  mod_proxy_ajp of Apache HTTP Server.  This issue affects Apache HTTP
  Server: through 2.4.66.  Users are recommended to upgrade to version
  2.4.67, which fixes the issue.  Credits: Elhanan Haenel

* SECURITY: CVE-2026-33523: Apache HTTP Server: multiple modules: HTTP
  response splitting forwarding malicious status line (cve.mitre.org) HTTP
  response splitting vulnerability in multiple Apache HTTP Server modules
  with untrusted or compromised backend servers.  This issue affects Apache
  HTTP Server: from through 2.4.66.  Users are recommended to upgrade to
  version 2.4.67, which fixes the issue.  Credits: Haruki Oyama (Waseda
  University)

* SECURITY: CVE-2026-33007: Apache HTTP Server: mod_authn_socache crash
  (cve.mitre.org) A NULL pointer dereference in the mod_authn_socache in
  Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote
  user to crash a child process in a caching forward proxy configuration.
  Users are recommended to upgrade to version 2.4.67, which fixes this
  issue.  Credits: Pavel Kohout, Aisle Research, Aisle.com

* SECURITY: CVE-2026-33006: Apache HTTP Server: mod_auth_digest timing
  attack (cve.mitre.org) A timing attack against mod_auth_digest in Apache
  HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote
  attacker.  Users are recommended to upgrade to version 2.4.67, which fixes
  this issue.  Credits: Nitescu Lucian

* SECURITY: CVE-2026-29169: Apache HTTP Server: mod_dav_lock indirect lock
  crash (cve.mitre.org) A NULL pointer dereference in mod_dav_lock in Apache
  HTTP Server 2.4.66 and earlier may allow an attacker to crash the server
  with a malicious request.mod_dav_lock is not used internally by mod_dav or
  mod_dav_fs.  The only known use-case for mod_dav_lock was mod_dav_svn from
  Apache Subversion earlier than version 1.2.0.  Users are recommended to
  upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.
  Credits: Pavel Kohout, Aisle Research, Aisle.com

* SECURITY: CVE-2026-29168: Apache HTTP Server: mod_md unrestricted OCSP
  response (cve.mitre.org) Allocation of Resources Without Limits or
  Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response
  data.  This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.
  Users are recommended to upgrade to version 2.4.67, which fixes the issue.
  Credits: Pavel Kohout, Aisle Research, Aisle.com

* SECURITY: CVE-2026-28780: Apache HTTP Server: buffer overflow in
  mod_proxy_ajp via ajp_msg_check_header() (cve.mitre.org) Heap-based Buffer
  Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.  If
  mod_proxy_ajp connects to a malicious AJP server this AJP server can send
  a malicious AJP message back to mod_proxy_ajp and cause it to write 4
  attacker controlled bytes after the end of a heap based buffer.  This
  issue affects Apache HTTP Server: through 2.4.66.  Users are recommended
  to upgrade to version 2.4.67, which fixes the issue.  Credits: Andrew
  Lacambra

* SECURITY: CVE-2026-24072: Apache HTTP Server: mod_rewrite elevation of
  privileges via ap_expr (cve.mitre.org) An escalation of privilege bug in
  various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess
  authors to read files with the privileges of the httpd user.  Users are
  recommended to upgrade to version 2.4.67, which fixes this issue.
  Credits: y7syeu

* SECURITY: CVE-2026-23918: Apache HTTP Server: http2: double free and
  possible RCE on early reset (cve.mitre.org) Double Free and possible RCE
  vulnerability in Apache HTTP Server with the HTTP/2 protocol.  This issue
  affects Apache HTTP Server: 2.4.66.  Users are recommended to upgrade to
  version 2.4.67, which fixes the issue.  Credits: Bartlomiej Dmitruk,
  striga.ai

* mod_md: update to version 2.6.10
  - Fix issue #420 <https://github.com/icing/mod_md/issues/420> by ignoring
    job.json files that claim to have completely finished a certificate
    renewal, but have not produced the necessary result files.

* mod_http2: update to version 2.0.39
  Remove streams own memory allocator after reports of memory problems with
  third party modules.  [Stefan Eissing]

* mod_http2: update to version 2.0.38
  Source sync with mod_h2 github repository. No functional change.  [Stefan
  Eissing]

* Updated conf/mime.types: added vnd.sqlite3, HEIC, HEIF
  [Alexandru Mărășteanu <hello alexei.ro>]

* mod_md: update to version 2.6.7
  - Fix a regression in `MDStapleOthers` which broke in v2.6.0 and no longer
    applied, no matter the configuration.

* mod_md: update to version 2.6.9
  - Pebble 2.9+ reports another error when terms of service agreement is not
    set. Treating all "userActionRequired" errors as permanent now.

* mod_md: update to version 2.6.8
  - Fix the ARI related `replaces` property in ACME order creation to only
    be used when the CA supports ARI and it is enabled in the menu config.
  - Fix compatibility with APR versions before 1.6.0 which do not have
    `apr_cstr_casecmp` and should use `apr_strnatcasecmp` instead.

* mod_http2: update to version 2.0.37
  Prevent double purge of a stream, resulting in a double free.  Fixes PR
  69899.  [Stefan Eissing]

* mod_md: Use correct function name when compiling against APR < 1.6.0.
  PR 69954 [Tần Quảng <baobaoxich@gmail.com>]
   2026-02-06 11:06:21 by Thomas Klausner | Files touched by this commit (1305)
Log message:
*: recursive bump for nettle 4.0 shlib major bump