The httpd flaws CVE-2021-40438 (bug 2005117) and CVE-2021-26691 (bug 1966732) were addressed in Red Hat Enterprise Linux 8 via erratum RHSA-2021:3816 released on Oct 12, 2021: https://access.redhat.com/errata/RHSA-2021:3816 However, those fixes were not included in the httpd update released as part of Red Hat Enterprise Linux 8.5, causing a security regression of previously released fixes. A new CVE id CVE-2021-20325 was assigned for this security regression. Note that this issue and CVE id is specific to the httpd packages as shipped with Red Hat Enterprise Linux 8 and is not applicable to any upstream httpd version as released by Apache Software Foundation or httpd packages of any other vendor that are not directly based on Red Hat Enterprise Linux 8 packages. For more information about the original flaws, refer to the specific flaw bugs linked above.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:4537 https://access.redhat.com/errata/RHSA-2021:4537
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-20325
The Red Hat Enterprise Linux 8.5 erratum that introduced this regression is: https://access.redhat.com/errata/RHSA-2021:4257