Apache HTTP Server mod_proxy_html Buffer Overflow Vulnerability

Vulnerability

A buffer overflow vulnerability has been identified in the mod_proxy_html module of Apache HTTP Server. This issue affects versions 2.4.67 and earlier, allowing an untrusted backend to execute an attack. The vulnerability can be exploited by sending crafted responses that manipulate memory, potentially leading to arbitrary code execution or causing the server to crash.

Impact

Exploitation of this vulnerability causes a buffer overflow, which can lead to memory corruption. In many cases, such buffer overflows can be exploited to execute arbitrary code under the user account of the web server.

Remediation

Users are advised to upgrade to Apache HTTP Server version 2.4.68, which addresses this vulnerability.

Added: Jun 8, 2026, 5:20 PM
Updated: Jun 8, 2026, 5:20 PM

Vulnerability Rating

Custom Algorithm
spread
9.4
impact
0.6
exploitability
7.6
remediation
7.7
relevance
9.4
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.