CVE-2026-34032

Security update for apache2

mediumEPSS 0.5%

Description

Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Metrics

Severity
medium
no public PoC known
5.3
Source: nvd-v3
40.2 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
0.5 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-27 14:44 UTC
CWE-170, CWE-125

Weakness classes (CWE)

  • CWE-170Base

    Improper Null Termination

    The product does not terminate or incorrectly terminates a string or array with a null character or equivalent terminator.

    cwe.mitre.org →
  • CWE-125Base

    Out-of-bounds Read

    The product reads data past the end, or before the beginning, of the intended buffer.

    cwe.mitre.org →

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • apache

    http_server2.4.67

  • bitnami

    apache2.4.0

  • bitnami

    apache2.4.30

  • bitnami

    apache2.4.66

  • bitnami

    apache

References & sources

Linked CVEs

IDCVE-2026-34032