PT-2026-103929 · Apache · Apache Http Server

·

CVE-2026-56449

·

Published

2026-10-01

·

Updated

2026-10-01

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.0 through 2.4.68
Description An out-of-bounds write issue exists in the mod proxy html module when processing specially crafted HTTP response bodies. An out-of-bounds write occurs when a program writes data past the end of the intended buffer, which can lead to memory corruption.
Recommendations Update Apache HTTP Server to a version later than 2.4.68. As a temporary mitigation, consider disabling the mod proxy html module if it is not required.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56449

Affected Products

Apache Http Server