| Author |
|
Steffen Moderator
Joined: 15 Oct 2005 Posts: 3207 Location: Hilversum, NL, EU
|
Posted: Wed 10 Jun '26 8:50 Post subject: Apache httpd 2.4.68 GA Available :: Update |
|
|
Apache httpd 2.4.68 is released as GA.
27 August 2026 Update, see below
ASF and Apachelounge changes : https://www.apachelounge.com/Changelog-2.4.html
Lot of security fixes. See the important security vulnerabilities fixed in 2.4.xx, https://httpd.apache.org/security/vulnerabilities_24.html .
Documentation: http://httpd.apache.org/docs/2.4/
Build with dependencies:
- openssl 3.6.4
- nghttp2 1.70.0
- jansson 2.15.1
- curl 8.21.0
- apr 1.7.6
- apr-util 1.6.5
- apr-iconv 1.2.2
- zlib 1.3.2
- zstd 1.5.7
- brotli 1.2.0
- pcre2 10.47
- libxml2 2.15.3
- lua 5.5.1
- expat 2.8.3
- nghttp3 1.18.0
- ngtcp2 1.25.0
Enjoy
Last edited by Steffen on Thu 27 Aug '26 9:17; edited 4 times in total |
|
| Back to top |
|
admin Site Admin

Joined: 15 Oct 2005 Posts: 760
|
Posted: Wed 10 Jun '26 19:31 Post subject: |
|
|
There are scanner reports that the downloaded file contains viruses, not all scanners.
Scanners like defender on Windows reports that all is fine. |
|
| Back to top |
|
axel.kam

Joined: 11 Jul 2023 Posts: 30
|
Posted: Thu 11 Jun '26 0:29 Post subject: |
|
|
| admin wrote: | | There are scanner reports that the downloaded file contains viruses, not all scanners. |
There are only one scanner report this.
I dont khow who is MaxSecure and can i trust them.
Install right now:
- I usually try to wait a few days before using any new product in production.
+ Serios CVE in http2 fixed there
- Virustotal reports
= Still wating few days before |
|
| Back to top |
|
BeWog
Joined: 28 Feb 2026 Posts: 4 Location: FR
|
Posted: Mon 15 Jun '26 9:21 Post subject: |
|
|
Hello
I had already pointed out some differences here : https://www.apachelounge.com/viewtopic.php?p=44157#44157
and there still here.
I would really appreciate it if you could replace all occurrences of error_log to error.log
and access_log to access.log.
Thanks  |
|
| Back to top |
|
admin Site Admin

Joined: 15 Oct 2005 Posts: 760
|
Posted: Mon 15 Jun '26 17:12 Post subject: |
|
|
Thank you for your response and apologies that we missed your earlier request.
The AL filename format changed with the switch to CMake builds, since the source official template file docs/conf/httpd.conf.in contains the references to access_log and error_log which end up in httpd.conf.
For as long as I can remember those have been the default names when building with CMake or using the configure script under Linux. The only exception I know is Apache builds on Ubuntu, which defaults to access.log and error.log.
We are not changing it. It is part of the official Apache source code.
You have to change it manual. |
|
| Back to top |
|
Steffen Moderator
Joined: 15 Oct 2005 Posts: 3207 Location: Hilversum, NL, EU
|
|
| Back to top |
|
ltdeta
Joined: 27 Feb 2015 Posts: 30 Location: Germany
|
Posted: Wed 17 Jun '26 16:50 Post subject: |
|
|
changelog file
The last update has the wrong date. It shows “07” instead of “17”.
| Quote: | | 07-June-2026 Changes with Apache 2.4.68 - Announcement |
|
|
| Back to top |
|
Steffen Moderator
Joined: 15 Oct 2005 Posts: 3207 Location: Hilversum, NL, EU
|
Posted: Wed 17 Jun '26 18:18 Post subject: |
|
|
Thanks!
Corrected. |
|
| Back to top |
|
Steffen Moderator
Joined: 15 Oct 2005 Posts: 3207 Location: Hilversum, NL, EU
|
|
| Back to top |
|
BeWog
Joined: 28 Feb 2026 Posts: 4 Location: FR
|
Posted: Thu 27 Aug '26 12:31 Post subject: |
|
|
Hello,
For your information, my antivirus (WithSecure) also flagged the latest version of C:\Apache24\bin\httpd.exe as suspicious.
Here is the translated message from WithSecure:
| Quote: |
27/08/2026 12:12
Suspicious behavior prevented
Path: C:\Apache24\bin
File: httpd.exe
Application hash: e77b058389c9ed22ae9ddda16719780ac0c232d2bb1c4f417b8763fe241d96fe
Reason: Suspicious:W32/Malware!DeepGuard.a
|
Regards. |
|
| Back to top |
|
admin Site Admin

Joined: 15 Oct 2005 Posts: 760
|
Posted: Thu 27 Aug '26 12:55 Post subject: |
|
|
| False positive. Defender etc. no issue. |
|
| Back to top |
|
tangent Moderator
Joined: 16 Aug 2020 Posts: 463 Location: UK
|
Posted: Wed 02 Sep '26 16:51 Post subject: |
|
|
This repeated alert from WithSecure annoys me, and I rather agree this is a false positive.
Apache builds are created using the latest release of MSVC (VS18), and since this warning appears to have kicked off within the last two builds, to me it suggests it's something to do with MSVC compiler changes, particularly code optimisations. There is mention of such 'improvements' earlier this year here:- https://devblogs.microsoft.com/cppblog/c-performance-improvements-in-msvc-build-tools-v14-51
I considered uploading a copy of the latest HTTPD binary to WithSecure to go through their Sample Validation service, requesting they consider whitelisting this signature. Unfortunately, it seems WithSecure retired its old public "Submit a Sample" system at the end of December 2025, and their replacement is a Sample Validation service in WithSecure Elements Security Center, which requires an authenticated WithSecure account.
So instead I uploaded the binary to the TotalVirus site for consideration, since it claims to use WithSecure amongst various vendor scanners:- https://www.virustotal.com/gui/home/upload
For me it currently shows no issues with the httpd.exe binary out of the httpd-2.4.68-260827-Win64-VS18.zip archive, based on some 70 AV scanners including WithSecure. The result is available here:- https://www.virustotal.com/gui/file/e77b058389c9ed22ae9ddda16719780ac0c232d2bb1c4f417b8763fe241d96fe - the details tab confirms this is the Apache Lounge binary.
Interestingly though, if I upload the current HTTPD archive then 1 vendor (MaxSecure) moans about 14 files, assorted other exe's and dll's. Again, WithSecure had no issue with any files in the archive.
MaxSecure was the company @axel.kam previously mentioned in this post, but either way to me this result suggests WithSecure scans should be happy with the Apache Lounge binaries. |
|
| Back to top |
|