Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44185

Опубликовано: 08 июн. 2026
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

A flaw was found in Apache HTTP Server. This buffer over-read vulnerability occurs when the server processes outbound Online Certificate Status Protocol (OCSP) requests directed to an attacker-controlled OCSP server. This could allow a remote attacker to read sensitive information from memory or cause a denial of service.

Отчет

A critical buffer over-read flaw in Apache HTTP Server occurs when it performs outbound OCSP requests. If a server connects to an attacker-controlled OCSP responder, a remote attacker can leak sensitive memory data or trigger a denial of service (DoS). This risk depends entirely on the server's OCSP configuration and endpoint trustworthiness.

Меры по смягчению последствий

To mitigate this issue, ensure that Apache HTTP Server is configured to only communicate with trusted OCSP responders. If OCSP validation or stapling is not a critical requirement for your deployment, consider disabling it. This can be achieved by adjusting mod_ssl directives in your Apache HTTP Server configuration. For example, add or modify the following lines:

SSLOCSPEnable off SSLUseStapling off

After modifying the configuration, reload the httpd service for the changes to take effect safely without interrupting active connections:

sudo systemctl reload httpd

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6httpdAffected
Red Hat Enterprise Linux 7httpdAffected
Red Hat Enterprise Linux 8httpdAffected
Red Hat Enterprise Linux 9httpdAffected
Red Hat Hardened ImageshttpdAffected
Red Hat Enterprise Linux 10httpdFixedRHSA-2026:3410901.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2486397httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server

EPSS

Процентиль: 45%
0.00598
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
около 2 месяцев назад

Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

CVSS3: 7.3
nvd
около 2 месяцев назад

Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

msrc
около 1 месяца назад

Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request`

CVSS3: 7.3
debian
около 2 месяцев назад

Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP ...

CVSS3: 7.3
github
около 2 месяцев назад

Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

EPSS

Процентиль: 45%
0.00598
Низкий

7.3 High

CVSS3