CVE-2026-34355
published 2026-06-08CVE-2026-34355: A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.94%
56.9th percentile
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.4.0 < 2.4.68 | 2.4.68 |
| apache | httpd | — | — |
| apache_software_foundation | apache_http_server | 2.4.0 – 2.4.67 | — |
| ubuntu | apache2 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_ubuntu9.8CRITICAL
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache HTTP Server up to 2.4.67 mod_proxy_html buffer overflow (EUVD-2026-35097)
vuldb·2026-06-13·CVSS 7.5
CVE-2026-34355 [HIGH] Apache HTTP Server up to 2.4.67 mod_proxy_html buffer overflow (EUVD-2026-35097)
A vulnerability was found in Apache HTTP Server up to 2.4.67. It has been classified as critical. The affected element is an unknown function of the component mod_proxy_html. This manipulation causes buffer overflow.
The identification of this vulnerability is CVE-2026-34355. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
GHSA
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend.
ghsa_unreviewed·2026-06-08
CVE-2026-34355 [HIGH] CWE-122 A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend.
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-07-08·CVSS 9.8
CVE-2026-44119 [CRITICAL] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
It was discovered that Apache HTTP Server's mod_ldap module incorrectly
handled memory when processing per-directory configurations. An attacker
could use this issue to cause the server to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2026-29167)
It was discovered that Apache HTTP Server's mod_proxy_ftp module
incorrectly handled HTML generation for FTP directory listings. A remote
attacker could possibly use this issue to inject arbitrary web script or
HTML. (CVE-2026-29170)
It was discovered that Apache HTTP Server's mod_proxy_html module
incorrectly handled certain content from an untrusted backend. A remote
attacker could possibly use this
Red Hat
httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass
vendor_redhat·2026-06-08·CVSS 7.5
CVE-2026-34355 [HIGH] CWE-120 httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass
httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
A vulnerability has been identified in the Apache HTTP Server. If the server is configured to connect to a malicious or compromised backend server, an attacker could exploit this flaw to bypass security controls or run unauthorized code on the system.
Statement: This Important vulnerability in `mod_proxy_html` within the Apache HTTP Server allows an untrusted backend to trigger a buffer overflow. This could lead to a security bypass or arbitrary code execution, posing a significant risk in environments where `htt
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-34355 httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass [fedora-all]
bugzilla·2026-06-18·CVSS 7.5
CVE-2026-34355 [HIGH] CVE-2026-34355 httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass [fedora-all]
CVE-2026-34355 httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34355 httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass
bugzilla·2026-06-08·CVSS 7.5
CVE-2026-34355 [HIGH] CVE-2026-34355 httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass
CVE-2026-34355 httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
Bugzilla
CVE-2026-48913 httpd: mod_http2: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service.
bugzilla·2026-06-08·CVSS 7.3
CVE-2026-48913 [HIGH] CVE-2026-48913 httpd: mod_http2: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service.
CVE-2026-48913 httpd: mod_http2: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service.
Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted.
This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:34355 https://access.redhat.com/errata/RHSA-2026:34355
https://httpd.apache.org/security/vulnerabilities_24.htmlhttp://www.openwall.com/lists/oss-security/2026/06/08/6https://access.redhat.com/errata/RHSA-2026:25042https://access.redhat.com/errata/RHSA-2026:34109https://access.redhat.com/security/cve/CVE-2026-34355https://bugzilla.redhat.com/show_bug.cgi?id=2486414https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34355.json
2026-06-08
Published