This is really just notable for an Apache bug surfacing in the news. They've been rare. Looking back at the 2.4 security page, request smuggling has been an ongoing bug class, as has the usual type of memory issues from C.
Last year Apache started down a path with Rust, providing modtls as a replacement for modssl. But it was the Internet Security Research Group that did the work, not the Apache Software Foundation. We'll add this to the list of projects to watch that are migrating away from C, but it's not clear whether there's more to come from httpd.