CVE-2026-34355

Apache HTTP Server vulnerabilities

Beschreibung

Ein Pufferüberlauf in `mod_proxy_html` im Apache HTTP Server 2.4.67 und früher ermöglicht einen Angriff durch ein nicht vertrauenswürdiges Backend. Benutzer werden empfohlen, auf Version 2.4.68 zu aktualisieren, die dieses Problem behebt.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.5
Quelle: nvd-v3
65.3 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
1.2 %
Moderat — Modell schätzt 1-10 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-07-20 19:03 UTC
CWE-122

Weakness-Klassen (CWE)

  • CWE-122Variant

    Heap-based Buffer Overflow

    A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-10 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/34xxx/CVE-2026-34355.json">CVE-2026-34355</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:66323
  2. CVE Modified2026-08-11 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:53371
    • Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8 (+4)Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8 (+5)
  3. CVE Modified2026-07-28 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:47046
    • Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 (+3)Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8 (+4)
  4. CVE Translated2026-07-23 07:10 UTC· nvd@nist.gov
    • Translation: Title: Apache HTTP Server, Description: Un desbordamiento de búfer en mod_proxy_html en el Servidor HTTP Apache 2.4.67 y anteriores permite un ataque por un backend no confiable. Se recomienda a los usuarios actualizar a la versión 2.4.68, que soluciona este problema.
  5. CVE Modified2026-07-22 12:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:42828
    • Affected: Red Hat Enterprise Linux 10, Red Hat Hardened Images, Red Hat Enterprise Linux 6 (+3)Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 (+3)

Betroffene Betriebssysteme

  • linux

    debian / debian_linux11.0

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • apache

    http_server2.4.0 – 2.4.68

  • bitnami

    apache2.4.0

  • bitnami

    apache2.4.17

  • bitnami

    apache2.4.55

  • bitnami

    apache

Quellen & Referenzen

Verknüpfte CVEs

Verknüpfte Empfehlungen

IDCVE-2026-34355