CVE-2026-29168: Apache HTTP Server: mod_md unrestricted OCSP response
Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's modmd via OCSP response data.
This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Other sources
Apache HTTP Server: modmd unrestricted OCSP response
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.4.67-1 - Upgrade
Upgrade
Apache HTTP Server mod_mdto a version that resolves this vulnerability.Fixed in 2.4.67Patch CVE-2026-29168
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29168?
CVE-2026-29168 is considered a serious vulnerability due to its potential for causing denial of service through resource exhaustion.
How do I fix CVE-2026-29168?
To fix CVE-2026-29168, upgrade your Apache HTTP Server to version 2.4.67 or later.
Which versions of Apache HTTP Server are affected by CVE-2026-29168?
CVE-2026-29168 affects Apache HTTP Server versions from 2.4.30 through 2.4.66.
What component of Apache HTTP Server does CVE-2026-29168 impact?
CVE-2026-29168 impacts the mod_md module specifically related to OCSP response processing.
Is there a workaround for CVE-2026-29168 if I cannot upgrade?
While upgrading is strongly recommended, temporarily limiting server resources or OCSP verification settings may reduce risk until an upgrade can be performed.