PT-2026-37041 · Apache+4 · Apache Http Server+4
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions 2.4.30 through 2.4.66
Description
An issue exists in the
mod md module where resource allocation occurs without limits or throttling when processing OCSP response data. OCSP (Online Certificate Status Protocol) is a protocol used to determine the current revocation status of a digital certificate.Recommendations
Upgrade to version 2.4.67.
Exploit
Fix
DoS
NULL Pointer Dereference
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Http Server
Linuxmint
Red Os
Rocky Linux
Ubuntu