PT-2026-47316 · Apache · Apache Http Server

Elhanan Haenel

+1

·

Published

2026-06-08

·

Updated

2026-06-08

·

CVE-2026-34355

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
A buffer overflow in mod proxy html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

Fix

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-34355

Affected Products

Apache Http Server