CVE-2026-34355: Apache HTTP Server: mod_proxy_html buffer overflow
A buffer overflow in modproxyhtml in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.67-1~deb11u3Fixed in 2.4.68-1 - Upgrade
Upgrade
Apache HTTP Server (mod_proxy_html)to a version that resolves this vulnerability.Fixed in 2.4.68
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34355?
The severity of CVE-2026-34355 is categorized as risk level 55, indicating a moderate buffer overflow vulnerability in mod_proxy_html.
How do I fix CVE-2026-34355?
To fix CVE-2026-34355, users should upgrade their Apache HTTP Server to version 2.4.68 or later.
Which versions of Apache HTTP Server are affected by CVE-2026-34355?
CVE-2026-34355 affects Apache HTTP Server version 2.4.67 and earlier.
What type of vulnerability is CVE-2026-34355?
CVE-2026-34355 is classified as a buffer overflow vulnerability.
Who is at risk from CVE-2026-34355?
All users of Apache HTTP Server 2.4.67 and earlier who are exposing their server to untrusted backends are at risk from CVE-2026-34355.