CVE-2025-53020

high
Published 2026-06-01 ยท Modified 2026-06-03
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
8.0

Description

Important: httpd:2.4 security update

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata โ€” Red Hat Inc. ยท View original โ†— ยท Open-Errata-API

Description mod_http2: Apache HTTP Server: HTTP/2 DoS by Memory Increase Red Hat statement The attack surface can be reduced by disabling HTTP/2 support in Apache. Follow the guidance in Red Hat KCS article to: - Remove h2 and h2c from the Protocols directive - Disable mod_http2 and mod_proxy_http2 modules (if not required) https://access.redhat.com/node/7056356 CVSS v3: 5.3โ€ฆ

Description

mod_http2: Apache HTTP Server: HTTP/2 DoS by Memory Increase

Red Hat statement

The attack surface can be reduced by disabling HTTP/2 support in Apache. Follow the guidance in Red Hat KCS article to: - Remove h2 and h2c from the Protocols directive - Disable mod_http2 and mod_proxy_http2 modules (if not required) https://access.redhat.com/node/7056356

CVSS v3: 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 10mod_http2-0:2.0.29-4.el10_2RHSA-2026:225282026-06-03T00:00:00Z
Red Hat Enterprise Linux 8httpd:2.4-8100020260519200905.489197e6RHSA-2026:221402026-06-01T00:00:00Z
Red Hat Enterprise Linux 9mod_http2-0:2.0.26-6.el9_8RHSA-2026:225512026-06-03T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6httpdNot affected
Red Hat Enterprise Linux 7httpdNot affected
Red Hat JBoss Core Servicesjbcs-httpd24-httpdAffected

Apply commands

bash fix
Apply RHSA-2026:22528 for Red Hat Enterprise Linux 10
yum update -y mod_http2
# or:
dnf upgrade -y mod_http2

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 6Not affected
redhatRed Hat Enterprise Linux 7Not affected
redhatRed Hat JBoss Core ServicesAffected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
8 Fixed httpd-filesystem-2.4.37-65.module_el8.10.0+4185+0955a0d7.8.noarch.rpm
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2.4.64-1
sid Fixed 2.4.64-1
forky Fixed 2.4.64-1
bullseye Fixed 2.4.65-1~deb11u1
bookworm Fixed 2.4.65-1~deb12u1
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed โ€”
8 Fixed โ€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.