Back

HIGH

Apache HTTP Server: mod_proxy_html buffer overflow

Published Jun 8, 2026

Description

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

Affected products

Remediation

Red Hat statement

This Important vulnerability in `mod_proxy_html` within the Apache HTTP Server allows an untrusted backend to trigger a buffer overflow. This could lead to a security bypass or arbitrary code execution, posing a significant risk in environments where `httpd` is configured with untrusted backend services.

Red Hat mitigation

Disable the `mod_proxy_html` module if it is not essential for your Apache HTTP Server configuration. If `mod_proxy_html` is required, restrict its use to trusted backend servers only, employing network segmentation and access controls. After modifying the configuration, reload the httpd service for changes to apply, which may cause a brief service interruption. Steps to disable: Open /etc/httpd/conf.modules.d/00-proxy.conf. Add a # to comment out the line: LoadModule proxy_html_module modules/mod_proxy_html.so Verify configuration syntax: apachectl configtest Apply the change gracefully: systemctl reload httpd

Metrics

References (18)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jun 8, 2026
Updated Sep 14, 2026
Reserved Mar 27, 2026
CISA Vulnrichment
Updated Jun 8, 2026
NVD
Status Modified
Modified Sep 14, 2026
Red Hat
Severity Important
Public date Jun 8, 2026