Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34356

Опубликовано: 08 июн. 2026
Источник: redhat
CVSS3: 7.5

Описание

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

A flaw was found in Apache HTTP Server. This heap-based buffer overflow vulnerability can be exploited by a malicious backend server when using ProxyPassReverseCookie* directives. This could lead to a denial of service (DoS) condition, making the server unavailable to legitimate users.

Отчет

This flaw in Apache could allow a malicious backend server to crash your web server, making it unavailable to users. Your system is only at risk if you use Apache to forward traffic to untrusted or unverified backend systems.

Меры по смягчению последствий

To prevent this denial-of-service flaw, ensure your Apache proxy rules only connect to highly trusted backend servers. If you must proxy traffic to unverified or external backends, disable the cookie-rewriting features. Steps to Mitigate: Open your Apache configuration file (e.g., /etc/httpd/conf/httpd.conf). Locate and comment out any ProxyPassReverseCookieDomain or ProxyPassReverseCookiePath lines pointing to untrusted backends by adding a # at the start of the line. Test your syntax: apachectl configtest Apply changes gracefully: systemctl reload httpd Note: This may cause a brief service interruption.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6httpdAffected
Red Hat Enterprise Linux 7httpdAffected
Red Hat Enterprise Linux 10httpdFixedRHSA-2026:3410901.07.2026
Red Hat Enterprise Linux 10.0 Extended Update SupporthttpdFixedRHSA-2026:4704628.07.2026
Red Hat Enterprise Linux 8httpdFixedRHSA-2026:4282821.07.2026
Red Hat Enterprise Linux 9httpdFixedRHSA-2026:4190620.07.2026
Red Hat Hardened Imageshttpd-main-2.4.68-1.hum1FixedRHSA-2026:2504210.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2486395httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

CVSS3: 7.5
nvd
около 2 месяцев назад

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

msrc
около 2 месяцев назад

Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow

CVSS3: 7.5
debian
около 2 месяцев назад

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with ma ...

CVSS3: 7.5
redos
4 дня назад

Уязвимость httpd

7.5 High

CVSS3