Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34356

Опубликовано: 08 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

A flaw was found in Apache HTTP Server. This heap-based buffer overflow vulnerability can be exploited by a malicious backend server when using ProxyPassReverseCookie* directives. This could lead to a denial of service (DoS) condition, making the server unavailable to legitimate users.

Отчет

This flaw in Apache could allow a malicious backend server to crash your web server, making it unavailable to users. Your system is only at risk if you use Apache to forward traffic to untrusted or unverified backend systems.

Меры по смягчению последствий

To prevent this denial-of-service flaw, ensure your Apache proxy rules only connect to highly trusted backend servers. If you must proxy traffic to unverified or external backends, disable the cookie-rewriting features. Steps to Mitigate: Open your Apache configuration file (e.g., /etc/httpd/conf/httpd.conf). Locate and comment out any ProxyPassReverseCookieDomain or ProxyPassReverseCookiePath lines pointing to untrusted backends by adding a # at the start of the line. Test your syntax: apachectl configtest Apply changes gracefully: systemctl reload httpd Note: This may cause a brief service interruption.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6httpdNot affected
Red Hat Enterprise Linux 7httpdNot affected
JBoss Core Services for RHEL 8jbcs-httpd24-httpdFixedRHSA-2026:5686819.08.2026
JBoss Core Services for RHEL 8jbcs-httpd24-mod_http2FixedRHSA-2026:5686819.08.2026
JBoss Core Services for RHEL 8jbcs-httpd24-mod_jkFixedRHSA-2026:5686819.08.2026
JBoss Core Services for RHEL 8jbcs-httpd24-mod_mdFixedRHSA-2026:5686819.08.2026
JBoss Core Services for RHEL 8jbcs-httpd24-mod_proxy_clusterFixedRHSA-2026:5686819.08.2026
JBoss Core Services for RHEL 8jbcs-httpd24-mod_securityFixedRHSA-2026:5686819.08.2026
Red Hat Enterprise Linux 10httpdFixedRHSA-2026:3410901.07.2026
Red Hat Enterprise Linux 10.0 Extended Update SupporthttpdFixedRHSA-2026:4704628.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2486395httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers

EPSS

Процентиль: 52%
0.00708
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

CVSS3: 7.5
nvd
3 месяца назад

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

msrc
3 месяца назад

Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow

CVSS3: 7.5
debian
3 месяца назад

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with ma ...

CVSS3: 7.5
redos
около 2 месяцев назад

Уязвимость httpd

EPSS

Процентиль: 52%
0.00708
Низкий

7.5 High

CVSS3

Уязвимость CVE-2026-34356