$summary
Thanks for the note in IRC, Agostino. I don't believe there is a security impact here. The only security fix noted by upstream in 2.2.18 was for CVE-2011-0419 in APR. I trust the Apache team to correct me, we don't use the bundled APR. We are currently handling CVE-2011-0419 in dev-libs/apr and dev-libs/apr-util via bug 366903.
2.2.18 contains some known regressions.