Software 44949 Published by

Apache HTTP Server 2.4.69 and stands out for a surprising reason: it ships with no new CVEs. Instead of chasing freshly patched vulnerabilities, the project focused on proactive hardening, dropping legacy RFC 2069 from its digest-auth rewrite, fixing a data-dropping HTTP/2 GOAWAY bug, and disabling a sensitive status handler by default. The release also ports the project's decades-old Perl test framework to Python and pytest, and adds OpenSSL 4 support plus a pile of smaller crash and protocol-abuse fixes. It's available now for download, requiring APR 1.5.x minimum, with no new features but a welcome return to maintenance-mode stability.



Apache HTTP Server 2.4.69 Ships With No New CVEs

The latest httpd release skips fresh advisories and doubles down on hardening, a digest-auth rewrite, and a Python test port.

The final version of Apache httpd 2.4.69 is now out after a release candidate, and it's the release most people will want for the most boring reason: it ships with no new CVEs.

Apachehttpd

The Apache Software Foundation put it out on October 1, 2026, and unlike the last couple of versions in the 2.4.x branch, it doesn't arrive under a security advisory. Apache calls it "the best version of Apache available," and it recommends upgrading from anything older.

That's a relief. The prior releases in this branch read like a checklist of buffer overflows, use-after-free errors, and privilege-escalation holes.

httpd is ancient by internet standards. It dates to 1995 and the NCSA, where developers spun up an open-source refinement of their older NCSA httpd code. "Apache" was a wry nod to the tribe whose land the datacenter sat on, implying the software had killed its own ancestor. It's now roughly three decades old and still runs a large share of the web, thanks to a modular design, .htaccess, virtual hosting, and broad portability.

The 2.4.x branch itself has been the stable line since 2012. It still requires APR 1.5.x and APR-Util 1.5.x, with some features wanting 1.6.x.

To see why 2.4.69 feels different, look at where the branch just came from. The last release, 2.4.68 in June 2026, packed in a big batch of CVEs: buffer overflows and underflows, use-after-free bugs, privilege escalation through .htaccess expressions, an infinite loop in mod_proxy_ftp, a stack over-read in mod_ssl OCSP handling, and an HTTP/2 denial-of-service. 2.4.67 and the ones before it weren't exactly spotless either.

So this one is hardening, not firefighting. Drop a legacy protocol, reject a malformed reason phrase, validate an integer, disable a status handler, rewrite fragile state handling. You're not putting out fires. You're reinforcing the load-bearing walls.

That said, the work still closes loops on recent failures. The digest-auth rewrite, for instance, builds on fixes that closed a timing-attack bypass in 2.4.66.

A Rewrite of Digest Authentication

The biggest change is a rewrite of mod_auth_digest, Apache's HTTP Digest authentication module, carried out by Joe Orton. Two things shifted.

First, it drops support for RFC 2069, the original spec that got superseded by RFC 2617. Keeping it around just gave attackers more surface area to poke at, so removing it shrinks the code that can be probed.

Second, the shared-memory and client-nonce handling were rewritten from scratch, and the "authdigest-opaque" mutex is no longer needed. Dropping that synchronization cuts out a class of subtle concurrency bugs and reduces the shared state that has to stay consistent under load.

Digest auth is a challenge-response scheme that lets a client prove it knows a password without sending it in the clear. It was valuable before TLS was everywhere, and it still turns up in some IoT and legacy enterprise setups. It's also been a recurring headache: CVE-2026-33006, a timing attack that let people bypass Digest auth entirely, was fixed just two releases ago in 2.4.66.

This one feels like closing the loop rather than patching individual symptoms. In a companion change, Eric Covener repaired a compatibility regression between mod_auth_digest and expression-based AuthName directives (PR 59039).

HTTP/2 Finally Drains on GOAWAY

Jim Jagielski fixed a correctness bug in mod_http2 that violated the spec and silently dropped responses.

Here's the scenario. When a client sends a graceful GOAWAY frame — the "I'm finishing up, no error" signal — while streams it opened are still processing, older code tore the session down immediately, discarding responses already in flight.

The new behavior drains the open streams first, then closes cleanly. It's now described as RFC 9113 compliant, which is the current HTTP/2 spec. Jagielski notes the bug "hits far more" on async MPMs than on the classic event MPM, because async request handling leaves more streams running at the same time.

A silently dropped response is exactly the kind of bug you can't reproduce in testing but that ruins your day in production, especially for APIs negotiating HTTP/2 upgrades.

This rides on a long streak of mod_http2 work from Stefan Eissing of greenbytes, who's shipped fixes for header accounting, file-handle exhaustion, window-size math, and stream double-frees across recent releases.

The Change You Won't See: Perl to Python

Jim Jagielski finished porting the old PERL-based test framework over to Python and pytest, now living in the source tree under ./test.

The test/ directory holds two independent pytest suites. pyhttpd/modules is httpd's own modern framework, covering HTTP/2, mod_md, HTTP/1.x, proxying, and core behavior, driving the server with curl and nghttp2/h2load. The pytest_suite is a self-contained port of the classic Perl Apache::Test suite, covering core HTTP, per-module tests, security/CVE regressions, SSL/TLS, and PHP, driving the server with an in-process Python client.

A single runner, run-all-tests.sh, executes both suites against the same build and reports a combined result. They spin up their own virtual environments with uv on first run, so contributors don't have to track down a decades-old Perl dependency.

That's the change with the longest horizon. Operators won't notice it, but it lowers the barrier to writing reliable regression tests — including fast checks against reported CVEs. It's an investment in making sure the silent-data-loss and crash bugs seen this release don't come back.

More Hardening, Smaller Cuts

A few more things landed along the way. Joe Orton made the server reject control characters in the reason phrase of interim responses and accept only a space as the status separator, a direct defense against HTTP response splitting and desynchronization attacks. It builds on fixes from 2.4.67 (CVE-2026-33523) and the broader CVE-2024-24795 line.

mod_substitute got two fixes. One makes SubstituteMaxLineLength reject values too large for the K/M/G suffix. The other prevents a crash when a Substitute directive is missing its closing delimiter.

mod_dir picked up a crash fix from Eric Covener (PR 68527) for requests not mapped to any type, closing another denial-of-service path. And mod_lbmethod_heartbeat, via Sayed Kaif, replaces an unsafe atoi() call with integer parsing that includes range validation.

mod_md, the ACME certificate-automation module, picked up OpenSSL 4 support and disabled MDServerStatus by default (Orton), so internal state about managed domains and certificates doesn't leak when someone loads the module. Keep in mind that this follows a pattern — mod_md has absorbed incremental robustness tweaks across recent releases for OCSP responses, ACME retry backoff, staging-directory corruption, and revocation detection.

A couple of compatibility fixes keep httpd interoperable. Craig Lorentzen of Amazon fixed OpenSSL compatibility macros for X509_get0_notBefore, X509_get0_notAfter, and X509_get0_serialNumber when building against OpenSSL below 1.1 (PR 70205), which spans everything from legacy pre-1.1 systems up to the new 4.x line.

And then there's the cosmetic closer: Jeffery To fixed the tar icon in the documentation so its background is transparent (PR 70238). It seems trivial until you've tried reading docs rendered with a solid white box behind every icon.

Get It

Apache HTTP Server 2.4.69 is available now from the official download page. You still need APR 1.5.x and APR-Util 1.5.x minimum (1.6.x for some features), and if you're using any threaded MPM other than Prefork, make sure your modules and their libraries are thread-safe.

Head here to the CHANGES_2.4.69 file for what changed since the prior release, the full 2.4 changelog for everything, and the vulnerabilities summary for the whole branch.

For what it's worth, 2.4.69 isn't the flashiest release in a while. It adds no feature. But after a stretch of releases that felt like a vulnerability dump, a clean one focused on hardening is about the best outcome you could ask for.