Apache HTTPD 2.4.69 Release Candidate Ships With HTTP 2 GOAWAY Fix

Published by

The Apache webserver has released its first release candidate for version 2.4.69, which includes significant changes aimed at improving HTTP/2 functionality. The most notable update is in the mod_http2 module, which now properly drains open streams instead of dropping them during a graceful GOAWAY, aligning with the current HTTP/2 standard RFC 9113. Additional enhancements include the disabling of MDServerStatus by default for better security, the removal of weak RFC 2069 digest authentication, and updates for OpenSSL 4 compatibility. The testing infrastructure has also been upgraded, transitioning from a Perl-based test suite to a Python and pytest framework, making future testing more efficient



Apache HTTPD 2.4.69 Release Candidate Ships With HTTP 2 GOAWAY Fix

The first release candidate for the Apache webserver 2.4.69 has been released for testing. The new candidate carries no fresh CVEs, since the heavy security work already landed in 2.4.68 back in June. Its biggest change makes mod_http2 drain open streams instead of dropping them on a graceful GOAWAY, bringing HTTP/2 in line with RFC 9113. Alongside that, the release disables MDServerStatus by default, drops weak RFC 2069 digest auth, adds OpenSSL 4 support, and ports the test suite from Perl to Python.

Apache HTTPD 2.4.69 Release Candidate Ships With HTTP 2 GOAWAY Fix @ Linux Compatible