AlmaLinux & Apache 2.4 & CVE-2021-42013 (+ other CVEs)

AlmaLinux is s 1:1 binary compatible with RHEL and is downstream from RHEL, so packages that get patched in RHEL will be patched in AlmaLinux also, usually with 1 business day of delay.

https://wiki.almalinux.org/Comparison.html

As you mentioned yourself you can use rpm -q --changelog PackageName | grep CVE to see if certain CVE is resolved in a package.

Packages in AlmaLinux come from RHEL, but get some small modifications before being made available in AlmaLinux.

https://wiki.almalinux.org/development/Packaging.html