CVE-2026-44185
published 2026-06-08CVE-2026-44185: Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server…
PriorityP348high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.60%
44.8th percentile
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.4.0 < 2.4.68 | 2.4.68 |
| apache | httpd | — | — |
| apache_software_foundation | apache_http_server | 2.4.0 – 2.4.67 | — |
| ubuntu | apache2 | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
vendor_ubuntu9.8CRITICAL
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 5.3
CVE-2026-34032 [MEDIUM] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server
incorrectly handled certain memory operations in mod_authn_socache. A
remote attacker could possibly use this issue to cause a denial of service.
(CVE-2026-33007)
Haruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache
HTTP Server had an HTTP response splitting vulnerability in multiple
modules when used with untrusted or compromised backend servers. An
attacker could possibly use this issue to inject arbitrary HTTP headers.
(CVE-2026-33523)
Elhanan Haenel discovered that Apache HTTP Server incorrectly handled
certain memory operations in mod_proxy_ajp. A remote attacker could
possibly use this i
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-07-08·CVSS 9.8
CVE-2026-44119 [CRITICAL] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
It was discovered that Apache HTTP Server's mod_ldap module incorrectly
handled memory when processing per-directory configurations. An attacker
could use this issue to cause the server to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2026-29167)
It was discovered that Apache HTTP Server's mod_proxy_ftp module
incorrectly handled HTML generation for FTP directory listings. A remote
attacker could possibly use this issue to inject arbitrary web script or
HTML. (CVE-2026-29170)
It was discovered that Apache HTTP Server's mod_proxy_html module
incorrectly handled certain content from an untrusted backend. A remote
attacker could possibly use this
Red Hat
httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server
vendor_redhat·2026-06-08·CVSS 7.3
CVE-2026-44185 [HIGH] CWE-125 httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server
httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
A flaw was found in Apache HTTP Server. This buffer over-read vulnerability occurs when the server processes outbound Online Certificate Status Protocol (OCSP) requests directed to an attacker-controlled OCSP server. This could allow a remote attacker to read sensitive information from memory or cause a denial of service.
Statement: A critical buffer over-read flaw in Apache HTTP Server occurs when it performs outbound OCSP requests.
GHSA
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
ghsa_unreviewed·2026-06-08
CVE-2026-44185 [HIGH] CWE-126 Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
VulDB
Apache HTTP Server up to 2.4.67 mod_ssl send_request stack-based overflow (EUVD-2026-35099 / Nessus ID 319665)
vuldb·2026-06-08·CVSS 7.3
CVE-2026-44185 [HIGH] Apache HTTP Server up to 2.4.67 mod_ssl send_request stack-based overflow (EUVD-2026-35099 / Nessus ID 319665)
A vulnerability marked as critical has been reported in Apache HTTP Server up to 2.4.67. Affected by this issue is the function send_request of the component mod_ssl. This manipulation causes stack-based buffer overflow.
This vulnerability is registered as CVE-2026-44185. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-44185 httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server [fedora-all]
bugzilla·2026-06-18·CVSS 7.3
CVE-2026-44185 [HIGH] CVE-2026-44185 httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server [fedora-all]
CVE-2026-44185 httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-44185 httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server
bugzilla·2026-06-08·CVSS 7.3
CVE-2026-44185 [HIGH] CVE-2026-44185 httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server
CVE-2026-44185 httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
https://httpd.apache.org/security/vulnerabilities_24.htmlhttp://www.openwall.com/lists/oss-security/2026/06/08/12https://access.redhat.com/errata/RHSA-2026:25042https://access.redhat.com/errata/RHSA-2026:34109https://access.redhat.com/errata/RHSA-2026:41906https://access.redhat.com/security/cve/CVE-2026-44185https://bugzilla.redhat.com/show_bug.cgi?id=2486397https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44185.json
2026-06-08
Published