Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-29168

Опубликовано: 05 мая 2026
Источник: redhat
CVSS3: 7.5

Описание

Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

A flaw was found in the mod_md module of httpd. When processing OCSP (Online Certificate Status Protocol) responses from a malicious or compromised OCSP responder, the module fails to enforce proper size limits on the incoming data. This issue leads to memory exhaustion and a denial of service.

Отчет

To exploit this flaw, the Apache HTTP Server must query an untrusted or compromised OCSP responder, limiting its exposure. Due to this reason, this vulnerability has been rated with a moderate severity. This flaw only affects configurations with mod_md loaded and being used. This module can be disabled via the configuration file if its functionality is not being used.

Меры по смягчению последствий

Disabling mod_md and restarting httpd will mitigate this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8httpd:2.4/mod_mdAffected
Red Hat Enterprise Linux 8mod_mdNot affected
JBoss Core Services for RHEL 8jbcs-httpd24-httpdFixedRHSA-2026:2720022.06.2026
JBoss Core Services for RHEL 8jbcs-httpd24-mod_mdFixedRHSA-2026:2720022.06.2026
JBoss Core Services on RHEL 7jbcs-httpd24-httpdFixedRHSA-2026:2720022.06.2026
JBoss Core Services on RHEL 7jbcs-httpd24-mod_mdFixedRHSA-2026:2720022.06.2026
Red Hat Enterprise Linux 10mod_mdFixedRHSA-2026:3084529.06.2026
Red Hat Enterprise Linux 9mod_mdFixedRHSA-2026:3084429.06.2026
Red Hat JBoss Core Services 2.4.62.SP4jbcs-httpd24-mod_mdFixedRHSA-2026:2720122.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2466753httpd: mod_md: unrestricted OCSP response leads to resource exhaustion

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
3 месяца назад

Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVSS3: 7.3
nvd
3 месяца назад

Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVSS3: 7.3
msrc
3 месяца назад

Apache HTTP Server: mod_md unrestricted OCSP response

CVSS3: 7.3
debian
3 месяца назад

Allocation of Resources Without Limits or Throttling vulnerability in ...

rocky
27 дней назад

Moderate: mod_md security update

7.5 High

CVSS3