CVE-2026-56449: Apache HTTP Server: mod_proxy_html: crash in dump_content
Published Oct 1, 2026
·Updated
Out-of-bounds Write vulnerability in Apache HTTP Server's modproxyhtml with crafted HTTP response bodies.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Affected Software
1 affected component
Apache HTTP Server>=2.4.0<=2.4.68
Event History
Oct 1, 2026
CVE Published
via MITRE·04:06 PM
Data Sourced
via MITRE·04:06 PM
DescriptionWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which Apache HTTP Server versions are affected?
Apache HTTP Server versions from 2.4.0 through 2.4.68 are affected.
2
What must an attacker control to trigger the issue?
An attacker needs to provide a crafted HTTP response body that is processed by mod_proxy_html.
3
What is the potential effect of successful exploitation?
The out-of-bounds write can cause Apache HTTP Server to crash.