Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34355

Опубликовано: 08 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

A vulnerability has been identified in the Apache HTTP Server. If the server is configured to connect to a malicious or compromised backend server, an attacker could exploit this flaw to bypass security controls or run unauthorized code on the system.

Отчет

This Important vulnerability in mod_proxy_html within the Apache HTTP Server allows an untrusted backend to trigger a buffer overflow. This could lead to a security bypass or arbitrary code execution, posing a significant risk in environments where httpd is configured with untrusted backend services.

Меры по смягчению последствий

Disable the mod_proxy_html module if it is not essential for your Apache HTTP Server configuration. If mod_proxy_html is required, restrict its use to trusted backend servers only, employing network segmentation and access controls. After modifying the configuration, reload the httpd service for changes to apply, which may cause a brief service interruption. Steps to disable: Open /etc/httpd/conf.modules.d/00-proxy.conf. Add a # to comment out the line: LoadModule proxy_html_module modules/mod_proxy_html.so Verify configuration syntax: apachectl configtest Apply the change gracefully: systemctl reload httpd

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6httpdAffected
Red Hat Enterprise Linux 7httpdAffected
JBoss Core Services for RHEL 8jbcs-httpd24-httpdFixedRHSA-2026:5686819.08.2026
JBoss Core Services for RHEL 8jbcs-httpd24-mod_http2FixedRHSA-2026:5686819.08.2026
JBoss Core Services for RHEL 8jbcs-httpd24-mod_jkFixedRHSA-2026:5686819.08.2026
JBoss Core Services for RHEL 8jbcs-httpd24-mod_mdFixedRHSA-2026:5686819.08.2026
JBoss Core Services for RHEL 8jbcs-httpd24-mod_proxy_clusterFixedRHSA-2026:5686819.08.2026
JBoss Core Services for RHEL 8jbcs-httpd24-mod_securityFixedRHSA-2026:5686819.08.2026
Red Hat Enterprise Linux 10httpdFixedRHSA-2026:3410901.07.2026
Red Hat Enterprise Linux 10.0 Extended Update SupporthttpdFixedRHSA-2026:4704628.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2486414httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass

EPSS

Процентиль: 65%
0.01161
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

CVSS3: 7.5
nvd
3 месяца назад

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

msrc
3 месяца назад

Apache HTTP Server: mod_proxy_html buffer overflow

CVSS3: 7.5
debian
3 месяца назад

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and e ...

CVSS3: 7.5
github
3 месяца назад

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

EPSS

Процентиль: 65%
0.01161
Низкий

7.5 High

CVSS3