PT-2026-103929 · Apache · Apache Http Server
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions 2.4.0 through 2.4.68
Description
An out-of-bounds write issue exists in the
mod proxy html module when processing specially crafted HTTP response bodies. An out-of-bounds write occurs when a program writes data past the end of the intended buffer, which can lead to memory corruption.Recommendations
Update Apache HTTP Server to a version later than 2.4.68.
As a temporary mitigation, consider disabling the
mod proxy html module if it is not required.Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Http Server