Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY135 SECURITY RECORDS

Apache Software Foundation

Apache HTTP Server

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2021-26691 10 Jun 2021 2.4.46; 2.4.43; 2.4.41; 2.4.39; 2.4.38; 2.4.37; 2.4.35; 2.4.34 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. Update reference ↗
CVE-2021-26690 10 Jun 2021 2.4.46; 2.4.43; 2.4.41; 2.4.39; 2.4.38; 2.4.37; 2.4.35; 2.4.34 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2020-35452 10 Jun 2021 2.4.46; 2.4.43; 2.4.41; 2.4.39; 2.4.38; 2.4.37; 2.4.35; 2.4.34 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2020-13950 10 Jun 2021 2.4.46; 2.4.43; 2.4.41 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2020-13938 10 Jun 2021 2.4.46; 2.4.43; 2.4.41; 2.4.39; 2.4.38; 2.4.37; 2.4.35; 2.4.34 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2019-17567 10 Jun 2021 2.4.46; 2.4.43; 2.4.41; 2.4.39; 2.4.38; 2.4.37; 2.4.35; 2.4.34 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2019-0197 11 Jun 2019 2.4.34 to 2.4.38 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 For the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted. After installing the updated packages, the httpd daemon will be restarted automatically. Update reference ↗
CVE-2019-0196 11 Jun 2019 2.4.17 to 2.4.38 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 For the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted. After installing the updated packages, the httpd daemon will be restarted automatically. Update reference ↗
CVE-2019-0220 11 Jun 2019 2.4.0 to 2.4.38 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2019-0190 30 Jan 2019 Apache HTTP Server 2.4.37 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2018-17199 30 Jan 2019 Apache HTTP Server 2.4.0 to 2.4.37 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 For the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted. After installing the updated packages, the httpd daemon will be restarted automatically. Update reference ↗
CVE-2018-17189 30 Jan 2019 2.4.17 to 2.4.37 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 For the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted. After installing the updated packages, the httpd daemon will be restarted automatically. Update reference ↗
CVE-2018-11763 25 Sep 2018 2.4.17 to 2.4.34 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. Update reference ↗
CVE-2016-4975 14 Aug 2018 Fixed in Apache HTTP Server 2.4.25 (Affected 2.4.1-2.4.23); Fixed in Apache HTTP Server 2.2.32 (Affected 2.2.0-2.2.31) Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2018-8011 18 Jul 2018 Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.33) No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2018-1333 18 Jun 2018 Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33) For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. Update reference ↗
CVE-2018-1312 26 Mar 2018 2.0.42 to 2.4.29 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. Update reference ↗
CVE-2018-1303 26 Mar 2018 2.4.5 to 2.4.29 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. Update reference ↗
CVE-2018-1302 26 Mar 2018 2.4.17 to 2.4.29 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. Update reference ↗
CVE-2018-1301 26 Mar 2018 2.2.0 to 2.4.29 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. Update reference ↗
CVE-2018-1283 26 Mar 2018 2.4.0 to 2.4.29 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. Update reference ↗
CVE-2017-15715 26 Mar 2018 2.4.0 to 2.4.29 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. Update reference ↗
CVE-2017-15710 26 Mar 2018 2.0.23 to 2.0.65; 2.2.0 to 2.2.34; 2.4.0 to 2.4.29 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. Update reference ↗
CVE-2017-9798 18 Sep 2017 Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. Update reference ↗
CVE-2016-8743 27 Jul 2017 2.2.0 to 2.2.31, 2.4.1 to 2.4.23 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. Update reference ↗
CVE-2016-2161 27 Jul 2017 2.4.0 to 2.4.23 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 For the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted. After installing the updated packages, the httpd daemon will be restarted automatically. Update reference ↗
CVE-2016-0736 27 Jul 2017 2.4.0 to 2.4.23 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 For the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted. After installing the updated packages, the httpd daemon will be restarted automatically. Update reference ↗
CVE-2017-7659 26 Jul 2017 2.4.24, 2.4.25 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2017-9789 13 Jul 2017 2.4.26 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2017-9788 13 Jul 2017 2.2.0 to 2.2.33; 2.4.1 to 2.4.26 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. Update reference ↗
CVE-2017-7679 20 Jun 2017 2.2.0 to 2.2.32; 2.4.0 to 2.4.25 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. Update reference ↗
CVE-2017-7668 20 Jun 2017 2.2.32; 2.4.24, 2.4.25 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2017-3169 20 Jun 2017 2.2.0 to 2.2.32; 2.4.0 to 2.4.25 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. Update reference ↗
CVE-2017-3167 20 Jun 2017 2.2.0 to 2.2.32; 2.4.0 to 2.4.25 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. Update reference ↗
CVE-2016-8740 5 Dec 2016 2.4.17 - 2.4.23 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 For the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted. After installing the updated packages, the httpd daemon will be restarted automatically. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.