CVE-2026-44185: Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request`
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.67-1~deb11u3Fixed in 2.4.68-1~deb12u1Fixed in 2.4.68-1~deb13u1Fixed in 2.4.68-1 - Upgrade
Upgrade
Apache HTTP Serverto a version that resolves this vulnerability.Fixed in 2.4.68
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44185?
CVE-2026-44185 is rated with a risk score of 23.
How do I fix CVE-2026-44185?
To fix CVE-2026-44185, upgrade Apache HTTP Server to version 2.4.68 or later.
What versions of Apache HTTP Server are affected by CVE-2026-44185?
CVE-2026-44185 affects Apache HTTP Server versions from 2.4.0 through 2.4.67.
What is the nature of the vulnerability described in CVE-2026-44185?
CVE-2026-44185 is a stack buffer over-read vulnerability that occurs during OCSP requests to an attacker-controlled server.
Is there a security patch available for CVE-2026-44185?
Yes, a security patch is included in Apache HTTP Server version 2.4.68 to address CVE-2026-44185.