Logo
vulnerabilityCVE-2026-34355
Name
CVE-2026-34355
Source
NVD ( link)Debian ( link)
Description
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
apache2
Exploitable

Vulnerability Ratings#


7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.4.68
Not Affected
buildroot
master
2.4.68
Not Affected
openwrt
master
2.4.65-r1
Exploitable
openwrt
openwrt-25.12
2.4.65-r1
Exploitable
yocto
kirkstone
2.4.66
Exploitable
yocto
scarthgap
2.4.67
Exploitable