Apache HTTP Server: mod_proxy_html buffer overflow
Published Jun 8, 2026
7.5
HIGHCVSS 3.1
EPSS 2.66%
Description
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
Affected products
-
- Version 2.4.0StatusaffectedConstraints<=2.4.67
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache HTTP Server | unaffected |
|
- ≥ 2.4.0 · < 2.4.68
No data.
JBoss Core Services for RHEL 8
jbcs-httpd24-httpd-0:2.4.62-16.el8jbcs
Fixed · RHSA-2026:56868
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_http2-0:2.0.29-13.el8jbcs
Fixed · RHSA-2026:56868
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_jk-0:1.2.50-17.redhat_1.el8jbcs
Fixed · RHSA-2026:56868
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_md-1:2.4.28-19.el8jbcs
Fixed · RHSA-2026:56868
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_proxy_cluster-0:1.3.22-12.el8jbcs
Fixed · RHSA-2026:56868
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_security-0:2.9.6-19.el8jbcs
Fixed · RHSA-2026:56868
Red Hat Enterprise Linux 10
httpd-0:2.4.63-13.el10_2.4
Fixed · RHSA-2026:34109
Red Hat Enterprise Linux 10.0 Extended Update Support
httpd-0:2.4.63-1.el10_0.4
Fixed · RHSA-2026:47046
Red Hat Enterprise Linux 8
httpd:2.4-8100020260714175253.489197e6
Fixed · RHSA-2026:42828
Red Hat Enterprise Linux 9
httpd-0:2.4.62-13.el9_8.5
Fixed · RHSA-2026:41906
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
httpd-0:2.4.53-11.el9_2.15
Fixed · RHSA-2026:67152
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
httpd-0:2.4.57-11.el9_4.5
Fixed · RHSA-2026:66323
Red Hat Enterprise Linux 9.6 Extended Update Support
httpd-0:2.4.62-4.el9_6.6
Fixed · RHSA-2026:62165
Red Hat Hardened Images
httpd-main-2.4.68-1.hum1
Fixed · RHSA-2026:25042
Red Hat Insights proxy 1.5
insights-proxy/insights-proxy-container-rhel9:1786433656
Fixed · RHSA-2026:53371
Red Hat Enterprise Linux 6
httpd
Affected
Red Hat Enterprise Linux 7
httpd
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Core Services for RHEL 8 | jbcs-httpd24-httpd-0:2.4.62-16.el8jbcs | Fixed | RHSA-2026:56868 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_http2-0:2.0.29-13.el8jbcs | Fixed | RHSA-2026:56868 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_jk-0:1.2.50-17.redhat_1.el8jbcs | Fixed | RHSA-2026:56868 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_md-1:2.4.28-19.el8jbcs | Fixed | RHSA-2026:56868 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_proxy_cluster-0:1.3.22-12.el8jbcs | Fixed | RHSA-2026:56868 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_security-0:2.9.6-19.el8jbcs | Fixed | RHSA-2026:56868 |
| Red Hat Enterprise Linux 10 | httpd-0:2.4.63-13.el10_2.4 | Fixed | RHSA-2026:34109 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | httpd-0:2.4.63-1.el10_0.4 | Fixed | RHSA-2026:47046 |
| Red Hat Enterprise Linux 8 | httpd:2.4-8100020260714175253.489197e6 | Fixed | RHSA-2026:42828 |
| Red Hat Enterprise Linux 9 | httpd-0:2.4.62-13.el9_8.5 | Fixed | RHSA-2026:41906 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | httpd-0:2.4.53-11.el9_2.15 | Fixed | RHSA-2026:67152 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | httpd-0:2.4.57-11.el9_4.5 | Fixed | RHSA-2026:66323 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | httpd-0:2.4.62-4.el9_6.6 | Fixed | RHSA-2026:62165 |
| Red Hat Hardened Images | httpd-main-2.4.68-1.hum1 | Fixed | RHSA-2026:25042 |
| Red Hat Insights proxy 1.5 | insights-proxy/insights-proxy-container-rhel9:1786433656 | Fixed | RHSA-2026:53371 |
| Red Hat Enterprise Linux 6 | httpd | Affected | n/a |
| Red Hat Enterprise Linux 7 | httpd | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This Important vulnerability in `mod_proxy_html` within the Apache HTTP Server allows an untrusted backend to trigger a buffer overflow. This could lead to a security bypass or arbitrary code execution, posing a significant risk in environments where `httpd` is configured with untrusted backend services.
Red Hat mitigation
Disable the `mod_proxy_html` module if it is not essential for your Apache HTTP Server configuration. If `mod_proxy_html` is required, restrict its use to trusted backend servers only, employing network segmentation and access controls. After modifying the configuration, reload the httpd service for changes to apply, which may cause a brief service interruption. Steps to disable: Open /etc/httpd/conf.modules.d/00-proxy.conf. Add a # to comment out the line: LoadModule proxy_html_module modules/mod_proxy_html.so Verify configuration syntax: apachectl configtest Apply the change gracefully: systemctl reload httpd
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Jun 8, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Jun–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (4 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.66% (0.02656) | 85.14th | v5 (v2026.06.15) |
| Sep 20, 2026 | 1.16% (0.01161) | 65.77th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.59% (0.00587) | 43.23th | v5 (v2026.06.15) |
| Jun 9, 2026 | 0.04% (0.00040) | 12.31th | v4 (v2025.03.14) |
References (18)
- http://www.openwall.com/lists/oss-security/2026/06/08/6 Mailing List
- https://access.redhat.com/errata/RHSA-2026:25042
- https://access.redhat.com/errata/RHSA-2026:34109
- https://access.redhat.com/errata/RHSA-2026:41906
- https://access.redhat.com/errata/RHSA-2026:42828
- https://access.redhat.com/errata/RHSA-2026:47046
- https://access.redhat.com/errata/RHSA-2026:53371
- https://access.redhat.com/errata/RHSA-2026:56868
- https://access.redhat.com/errata/RHSA-2026:56869
- https://access.redhat.com/errata/RHSA-2026:62165
- https://access.redhat.com/errata/RHSA-2026:66323
- https://access.redhat.com/errata/RHSA-2026:67152
- https://access.redhat.com/security/cve/CVE-2026-34355 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2486414 Issue Tracking
- https://httpd.apache.org/security/vulnerabilities_24.html vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-34355
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34355.json
- https://www.cve.org/CVERecord?id=CVE-2026-34355
Change history (0)
No recorded changes yet.