CVE-2026-34356
published 2026-06-08CVE-2026-34356: Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.68%
48.4th percentile
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie*
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.4.0 < 2.4.68 | 2.4.68 |
| apache | httpd | — | — |
| apache_software_foundation | apache_http_server | 2.4.0 – 2.4.67 | — |
| ubuntu | apache2 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_ubuntu9.8CRITICAL
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache HTTP Server up to 2.4.67 buffer overflow (EUVD-2026-35089)
vuldb·2026-06-09·CVSS 7.5
CVE-2026-34356 [HIGH] Apache HTTP Server up to 2.4.67 buffer overflow (EUVD-2026-35089)
A vulnerability was found in Apache HTTP Server up to 2.4.67. It has been declared as critical. The impacted element is an unknown function. Such manipulation leads to buffer overflow.
This vulnerability is referenced as CVE-2026-34356. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
GHSA
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
ghsa_unreviewed·2026-06-08
CVE-2026-34356 [HIGH] CWE-122 Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie*
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-07-08·CVSS 9.8
CVE-2026-44119 [CRITICAL] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
It was discovered that Apache HTTP Server's mod_ldap module incorrectly
handled memory when processing per-directory configurations. An attacker
could use this issue to cause the server to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2026-29167)
It was discovered that Apache HTTP Server's mod_proxy_ftp module
incorrectly handled HTML generation for FTP directory listings. A remote
attacker could possibly use this issue to inject arbitrary web script or
HTML. (CVE-2026-29170)
It was discovered that Apache HTTP Server's mod_proxy_html module
incorrectly handled certain content from an untrusted backend. A remote
attacker could possibly use this
Red Hat
httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers
vendor_redhat·2026-06-08·CVSS 7.5
CVE-2026-34356 [HIGH] CWE-120 httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers
httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie*
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
A flaw was found in Apache HTTP Server. This heap-based buffer overflow vulnerability can be exploited by a malicious backend server when using ProxyPassReverseCookie* directives. This could lead to a denial of service (DoS) condition, making the server unavailable to legitimate users.
Statement: This flaw in Apache could allow a malicious backend server to crash your web server, making it unavailable to users. Your system is only at risk if you
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-34356 httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers [fedora-all]
bugzilla·2026-06-18·CVSS 7.5
CVE-2026-34356 [HIGH] CVE-2026-34356 httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers [fedora-all]
CVE-2026-34356 httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34356 httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers
bugzilla·2026-06-08·CVSS 7.5
CVE-2026-34356 [HIGH] CVE-2026-34356 httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers
CVE-2026-34356 httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie*
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
2026-06-08
Published