https://seclists.org/oss-sec/2026/q2/841: CVE-2026-44185: Apache HTTP Server: Stack Buffer Over-ad in mod_ssl OCSP `send_quest`
Published Jun 8, 2026
·Updated
Affected Software
1 affected component
Apache HTTP Server>=2.4.0<=2.4.67
Frequently Asked Questions
1
What is the severity of CVE-2026-44185?
The severity of CVE-2026-44185 is classified as low.
2
Which versions of Apache HTTP Server are affected by CVE-2026-44185?
CVE-2026-44185 affects Apache HTTP Server versions 2.4.0 through 2.4.67.
3
How do I fix CVE-2026-44185?
To fix CVE-2026-44185, users are recommended to upgrade to a patched version of Apache HTTP Server.
4
What type of vulnerability is CVE-2026-44185?
CVE-2026-44185 is a buffer over-read vulnerability in mod_ssl's OCSP send_quest.
5
What is the impact of CVE-2026-44185 on users?
The impact of CVE-2026-44185 includes potential exposure to malicious OCSP servers, though it is rated low severity.