Apache HTTP Server 2.4.39 fixed six vulnerabilities: CVE-2019-0196, CVE-2019-0197, CVE-2019-0211, CVE-2019-0215, CVE-2019-0217, and CVE-2019-0220. The issues included HTTP/2 memory-safety and crash conditions, a local privilege-escalation flaw affecting Unix MPMs, a TLS 1.3 client-certificate authorization bypass, an authentication race that could permit user impersonation, and inconsistent handling of repeated URL-path slashes. F5 reported that its supported products were not affected by CVE-2019-0196, CVE-2019-0197, or CVE-2019-0220.
Apache’s broader 2.4 security record also documented risks in optional HTTP/2, proxy, session, TLS, and authentication components, including access-control bypasses and potential information disclosure or remote code execution in mod_proxy_uwsgi. Debian subsequently issued an LTS update for Debian 9’s apache2 package, version 2.4.25-3+deb9u10, fixing seven vulnerabilities—including CVE-2020-1927, CVE-2020-1934, CVE-2020-35452, CVE-2021-26690, CVE-2021-26691, CVE-2021-30641, and CVE-2021-31618—that could cause denial of service or incorrect MergeSlashes behavior; affected systems should upgrade their Apache packages.

See real exploitation activity before you spend the cycle.
20 events from the most recent confirmed update back to the earliest known activity.
Debian LTS issued DLA-2706-1 for apache2 on Debian 9 (stretch), updating the package to 2.4.25-3+deb9u10. The advisory fixed seven CVEs, including denial-of-service issues and unexpected MergeSlashes behavior, and recommended administrators upgrade affected packages.
Red Hat issued low-severity RHSA-2020:0251, updating JBoss Core Services Apache HTTP Server to 2.4.37 Service Pack 1 for RHEL 6, RHEL 7, and Microsoft Windows. The update replaced the prior 2.4.37 release and remediated CVE-2019-0220, an URL-normalization inconsistency.
Red Hat released RHSA-2020:0250 to fix CVE-2019-0220 in JBoss Core Services Apache HTTP Server packages, including jbcs-httpd24-httpd, on RHEL 6. Red Hat stated that base RHEL 6 would receive no future fix for the low-impact flaw because it was in Maintenance Support 2.
Debian published DSA-4509-1 to remediate six Apache HTTP Server vulnerabilities, including HTTP/2 denial-of-service, memory-corruption, use-after-free, XSS, mod_remoteip, and open-redirect flaws. It updated apache2 to 2.4.25-3+deb9u8 for oldstable stretch and 2.4.38-3+deb10u1 for stable buster, and advised users to upgrade.
CVE-2019-0220 was published for Apache HTTP Server 2.4.0 through 2.4.38. The flaw stems from inconsistent handling of consecutive URL slashes, which can cause LocationMatch and RewriteRule security-relevant request matching to differ from other path processing.
Debian issued DSA-4422-1 for apache2 in Debian stable (stretch), updating the package to 2.4.25-3+deb9u7. The update remediated six Apache vulnerabilities, including HTTP/2 denial-of-service and use-after-free flaws, a root privilege escalation, an authentication bypass, cookie-expiry handling failure, and URL-normalization inconsistency.
Apache HTTP Server 2.4.44 fixed CVE-2020-9490, CVE-2020-11984, and CVE-2020-11993. The fixes addressed an HTTP/2 Cache-Digest crash, a mod_proxy_uwsgi buffer overflow with possible disclosure or code execution, and unsafe concurrent memory-pool use in mod_http2 logging.
Apache HTTP Server 2.4.42 fixed CVE-2020-1927, an open redirect in certain mod_rewrite configurations, and CVE-2020-1934, a mod_proxy_ftp use-of-uninitialized-value issue when communicating with a malicious FTP backend.
Apache HTTP Server 2.4.41 fixed CVE-2019-9517, CVE-2019-10081, CVE-2019-10082, CVE-2019-10092, CVE-2019-10097, and CVE-2019-10098. The issues included HTTP/2 worker exhaustion, memory corruption and use-after-free conditions, a mod_remoteip overflow, proxy error-page XSS, and an open redirect.
Red Hat remediated CVE-2019-0220 for RHEL 7 through RHSA-2019:2343, RHEL 8 through RHSA-2019:3436, and selected Red Hat Software Collections releases through RHSA-2019:4126. Red Hat did not plan a RHEL 6 fix because the low-impact issue fell under Maintenance Support 2.
F5 Product Development evaluated CVE-2019-0196, CVE-2019-0197, and CVE-2019-0220 and found no currently supported F5 products vulnerable. It marked its advisory final unless new information emerged.
Fedora announced a security update for Fedora 28 providing the httpd-2.4.39-1.1.fc28 package. This is a separate downstream distribution update from the Apache 2.4.39 release and Debian advisories already recorded.
Fedora announced a security update for Fedora 29 providing the httpd-2.4.39-2.fc29 package. This is a distinct downstream update from the Fedora 28 httpd update already recorded.
Fedora promoted httpd-2.4.39-2.fc30 to the Fedora 30 stable repository after submitting it as a high-severity httpd security update and testing it. The tracking record was associated with CVE-2019-0211 but did not disclose all vulnerabilities remediated by the package.
Debian LTS issued DLA-1748-1 for apache2 on Debian 8 Jessie, updating the package to version 2.4.10-10+deb8u14. The update remediated CVE-2019-0217, a threaded mod_auth_digest impersonation and access-control bypass flaw, and CVE-2019-0220, an inconsistent URL-normalization issue.
Apache HTTP Server 2.4.39 fixed CVE-2019-0196, CVE-2019-0197, CVE-2019-0211, CVE-2019-0215, CVE-2019-0217, and CVE-2019-0220. The fixes addressed HTTP/2 memory-safety and crash issues, Unix local privilege escalation, TLS 1.3 client-certificate access-control bypass, Digest-authentication impersonation, and URL slash-normalization inconsistencies.
Apache HTTP Server 2.4.38 fixed CVE-2018-17189, CVE-2018-17199, and CVE-2019-0190. These included an HTTP/2 slow-request-body DoS, session-expiry bypasses in mod_session_cookie, and an infinite-loop DoS in mod_ssl client renegotiation.
Apache HTTP Server 2.4.35 fixed CVE-2018-11763, in which continuous maximum-size HTTP/2 SETTINGS frames could keep server connections busy indefinitely.
Apache HTTP Server 2.4.34 fixed CVE-2018-1333, an HTTP/2 worker-exhaustion denial of service, and CVE-2018-8011, a mod_md NULL-pointer dereference that could crash a child process.
Apache HTTP Server 2.4.33 fixed CVE-2017-15710, CVE-2017-15715, CVE-2018-1283, CVE-2018-1301, CVE-2018-1302, CVE-2018-1303, and CVE-2018-1312. The issues included LDAP and FilesMatch bypasses, session-data tampering, HTTP/2 memory-safety flaws, and weak Digest nonces.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
17 references tracked. Mallory keeps watching after this page renders.
cve.org
Open sourceaccess.redhat.com
Open sourceusn.ubuntu.com
Open sourcelists.debian.org
Open sourcelists.apache.org
Open sourcebugzilla.redhat.com
Open sourcelists.apache.org
Open sourcelists.debian.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.