The updated packages fix security vulnerabilities:
Apache HTTP Server: modldap per-dir use-after-free. (CVE-2026-29167)
Apache HTTP Server: modproxyftp XSS. (CVE-2026-29170)
Apache HTTP Server: modproxyhtml buffer overflow. (CVE-2026-34355)
Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow.
(CVE-2026-34356)
Apache HTTP Server: moddavfs protected directory access.
(CVE-2026-42535)
Apache HTTP Server: modxml2enc heap overflow. (CVE-2026-42536)
Apache HTTP Server: OOB Read in merge_response_headers can cause
crash. (CVE-2026-43951)
Apache HTTP Server: escalation of privilege through expressions in
.htaccess in multiple modules. (CVE-2026-44119)
Apache HTTP Server: Stack Buffer Over-Read in modssl OCSP
send_request. (CVE-2026-44185)
Apache HTTP Server: Loop in proxy_ftp_handler in modproxyftp.
(CVE-2026-44186)
Apache HTTP Server: Heap Underflow in ap_regname via Signed Char
Overflow. (CVE-2026-44631)
Apache HTTP Server: modhttp2 memory corruption when file handles
exhausted. (CVE-2026-48913)
Apache HTTP Server: mod_http2 denial of service. (CVE-2026-49975)