CVE-2026-34356: Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.67-1~deb11u3Fixed in 2.4.68-1~deb12u1Fixed in 2.4.68-1~deb13u1Fixed in 2.4.68-1 - Upgrade
Upgrade
Apache HTTP Serverto a version that resolves this vulnerability.Fixed in 2.4.68
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34356?
CVE-2026-34356 has a risk score of 58, indicating a moderate severity level.
How do I fix CVE-2026-34356?
To fix CVE-2026-34356, users should upgrade their Apache HTTP Server to version 2.4.68 or later.
Which versions of Apache HTTP Server are affected by CVE-2026-34356?
CVE-2026-34356 affects Apache HTTP Server versions from 2.4.0 through 2.4.67.
What type of vulnerability is CVE-2026-34356?
CVE-2026-34356 is classified as a heap-based buffer overflow vulnerability.
What impact does CVE-2026-34356 have on Apache HTTP Server?
CVE-2026-34356 can be exploited by malicious backend servers when using ProxyPassReverseCookie*, potentially compromising the server's memory.