ZeroHour

CVE-2026-34355

CVSS 3.1
7.5 high
EPSS
1%p65
Published
()
Modified
Description

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

Vendors
apache
Products
http server
Weakness
CWE-122, CWE-120
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.