Red Hat released multiple security advisories for mod_md to address CVE-2026-29168, a Moderate-severity flaw in Apache HTTP Server's managed domain module that can allow resource exhaustion through unrestricted OCSP responses. The updates cover several RHEL 9 streams, including 9.2, 9.4, and 9.6 variants for standard, SAP, and extended lifecycle channels across x86_64, aarch64, ppc64le, and s390x, with fixed package versions including mod_md-2.4.19-1.el9_2.2, mod_md-2.4.19-1.el9_4.2, and mod_md-2.4.26-1.el9_6.2.
Red Hat also rolled the fix into Red Hat JBoss Core Services Apache HTTP Server 2.4.62 Service Pack 4, which replaces Service Pack 3 and bundles broader security remediation for Apache HTTP Server components and dependencies. Those updates address additional issues in mod_proxy_ajp, mod_http2, mod_authn_socache, mod_dav_lock, and the bundled nghttp2 library, including a separate nghttp2 denial-of-service flaw, CVE-2026-27135, caused by malformed HTTP/2 frames after session termination that could trigger an assertion failure before version 1.68.1.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2026:57641 for RHEL 9.6 support channels, releasing mod_md 2.4.26-1.el9_6.2 to fix CVE-2026-29168. The advisory applies to Extended Update Support and related SAP Solutions and Extended Life Cycle channels across multiple architectures.
Red Hat issued RHSA-2026:57844 for multiple RHEL 9.4 variants, releasing mod_md-2.4.19-1.el9_4.2 to address CVE-2026-29168. The advisory covers SAP Solutions, Extended Life Cycle, and 4-years-of-updates offerings across x86_64, aarch64, ppc64le, and s390x.
Red Hat issued RHSA-2026:57642 for RHEL 9.2 channels, providing mod_md 2.4.19-1.el9_2.2 to fix CVE-2026-29168. Red Hat describes the flaw as an unrestricted OCSP response issue in httpd mod_md that can cause resource exhaustion.
Red Hat published RHSA-2026:27200 and RHSA-2026:27201 for Red Hat JBoss Core Services Apache HTTP Server 2.4.62 Service Pack 4, replacing Service Pack 3 and fixing multiple vulnerabilities. The updates include fixes for CVE-2026-27135 in nghttp2 and CVE-2026-29168 in mod_md, along with several Apache HTTP Server, OpenSSL, and Expat issues.
Red Hat documented CVE-2026-27135 as a denial-of-service flaw in nghttp2 versions prior to 1.68.1, caused by missing internal state validation after session termination that can lead to an assertion failure when malformed HTTP/2 frames are processed. The bug record states nghttp2 1.68.1 fixes the issue and that no workaround is known.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.