CVE-2026-29167: Apache HTTP Server: mod_ldap per-dir use-after-free
Published Jun 8, 2026
·Updated
Last updated 8 July 2026
Other sources
Use After Free vulnerability in Apache HTTP Server with modldap in per-directory configuration
— Launchpad
Affected Software
4 affected componentsFixes available
Apache HTTP Server>=2.4.0<=2.4.67
Apache HTTP Server>=2.4.0<2.4.68
Microsoft azl3 httpd 2.4.67-1
debian/apache2<=2.4.62-1~deb11u1, <=2.4.67-1~deb12u3, <=2.4.67-1~deb13u3
2.4.67-1~deb11u32.4.68-1~deb12u12.4.68-1~deb13u12.4.68-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.67-1~deb11u3Fixed in 2.4.68-1~deb12u1Fixed in 2.4.68-1~deb13u1Fixed in 2.4.68-1 - Upgrade
Upgrade
Apache HTTP Serverto a version that resolves this vulnerability.Fixed in 2.4.68Patch CVE-2026-29167
Event History
Jun 8, 2026
CVE Published
via MITRE·03:07 PM
Data Sourced
via MITRE·03:07 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Jun 11, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeaknessAffected Software
Jul 22, 2026
Data Sourced
via Ubuntu·08:18 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·08:20 PM
DescriptionAffected Software
Data Sourced
via Launchpad·08:20 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-29167?
The severity of CVE-2026-29167 is rated at 51.
2
How do I fix CVE-2026-29167?
To fix CVE-2026-29167, upgrade to Apache HTTP Server version 2.4.68 or later.
3
Which versions of Apache HTTP Server are affected by CVE-2026-29167?
CVE-2026-29167 affects Apache HTTP Server versions from 2.4.0 through 2.4.67.
4
What type of vulnerability is CVE-2026-29167?
CVE-2026-29167 is classified as a Use After Free vulnerability.
5
What components of Apache HTTP Server does CVE-2026-29167 involve?
CVE-2026-29167 involves the mod_ldap module in per-directory configuration.