A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade httpd-toolsUpgrade mod_mdUpgrade mod_proxy_htmlUpgrade httpd-develUpgrade mod_sslUpgrade httpdUpgrade httpd-manualUpgrade httpd-coreUpgrade mod_http2Upgrade mod_luaUpgrade httpd-filesystemUpgrade mod_ldapUpgrade mod_session | Jul 21, 2026 | Jul 20, 2026 |
| Alpine Linux | — | Upgrade apache2 | Jul 7, 2026 | Jun 8, 2026 |
| Amazon Linux Ami 2 | — | Upgrade httpd-develUpgrade httpd-debuginfoUpgrade mod_sslUpgrade mod_mdUpgrade httpd-manualUpgrade mod_sessionUpgrade mod_ldapUpgrade mod_proxy_htmlUpgrade httpdUpgrade httpd-filesystemUpgrade httpd-tools | Jun 23, 2026 | Jun 23, 2026 |
| Amazon_linux_2023 | — | Upgrade mod_ldap-debuginfoUpgrade httpd-manualUpgrade mod_proxy_html-debuginfoUpgrade httpd-coreUpgrade httpd-debuginfoUpgrade httpd-filesystemUpgrade httpd-develUpgrade httpdUpgrade mod_sessionUpgrade mod_proxy_htmlUpgrade mod_session-debuginfoUpgrade mod_sslUpgrade httpd-debugsourceUpgrade mod_ldapUpgrade httpd-toolsUpgrade httpd-core-debuginfoUpgrade mod_lua-debuginfoUpgrade mod_luaUpgrade httpd-tools-debuginfoUpgrade mod_ssl-debuginfo | Jun 23, 2026 | Jun 8, 2026 |
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Jun 9, 2026 | Jun 8, 2026 |
| Debian | — | Upgrade apache2 | Jun 16, 2026 | Jun 16, 2026 |
| Freebsd | — | Upgrade apache24 | Jun 15, 2026 | Jun 8, 2026 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Aug 16, 2026 | Aug 13, 2026 |
| Redhat_linux | — | Upgrade mod_lua-debuginfoUpgrade mod_md-debuginfoUpgrade httpd-debuginfoUpgrade httpd-develUpgrade mod_sessionUpgrade httpdUpgrade httpd-coreUpgrade httpd-tools-debuginfoUpgrade mod_luaUpgrade httpd-toolsUpgrade httpd-debugsourceUpgrade mod_proxy_htmlUpgrade httpd-core-debuginfoUpgrade mod_md-debugsourceUpgrade httpd-manualUpgrade mod_session-debuginfoUpgrade mod_ldap-debuginfoUpgrade httpd-filesystemNo solution existsUpgrade mod_mdUpgrade mod_ssl-debuginfoUpgrade mod_sslUpgrade mod_http2-debugsourceUpgrade mod_proxy_html-debuginfoUpgrade mod_ldapUpgrade mod_http2Upgrade mod_http2-debuginfo | Jul 3, 2026 | Jun 8, 2026 |
| Rocky_linux | — | Upgrade mod_http2-debuginfoUpgrade mod_luaUpgrade httpd-develUpgrade mod_md-debugsourceUpgrade mod_ssl-debuginfoUpgrade httpd-coreUpgrade httpd-toolsUpgrade httpd-tools-debuginfoUpgrade httpdUpgrade httpd-core-debuginfoUpgrade httpd-debugsourceUpgrade mod_proxy_htmlUpgrade mod_mdUpgrade mod_session-debuginfoUpgrade mod_md-debuginfoUpgrade mod_http2Upgrade mod_ldapUpgrade mod_http2-debugsourceUpgrade httpd-debuginfoUpgrade mod_lua-debuginfoUpgrade mod_sslUpgrade mod_ldap-debuginfoUpgrade mod_sessionUpgrade mod_proxy_html-debuginfo | Jul 10, 2026 | Jul 7, 2026 |
| Ubuntu | — | Upgrade apache2-suexec-custom (Ubuntu Pro)Upgrade apache2-bin (Ubuntu Pro)Upgrade libapache2-mod-proxy-uwsgi (Ubuntu Pro)Upgrade apache2-mpm-itk (Ubuntu Pro)Upgrade apache2-mpm-event (Ubuntu Pro)Upgrade apache2-utils (Ubuntu Pro)Upgrade apache2-mpm-worker (Ubuntu Pro)Upgrade apache2-suexec (Ubuntu Pro)Upgrade apache2-ssl-dev (Ubuntu Pro)Upgrade apache2-dev (Ubuntu Pro)Upgrade apache2.2-bin (Ubuntu Pro)Upgrade libapache2-mod-macro (Ubuntu Pro)Upgrade libapache2-mod-proxy-html (Ubuntu Pro)Upgrade libapache2-mod-md (Ubuntu Pro)Upgrade apache2-suexec-pristine (Ubuntu Pro)Upgrade apache2-mpm-prefork (Ubuntu Pro)Upgrade apache2 (Ubuntu Pro)Upgrade apache2 | Jul 9, 2026 | Jul 8, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub