oM noM Security Feeds cve
vulnerability context

CVE-2026-34355

CVSS 7.5 HIGHEPSS 42%CWE-122OTX 4 pulses

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

Published 2026-06-08 · last modified 2026-06-17

details

CISA KEV status
Not in catalog
CVSS v3
7.5 / HIGH
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
42% percentile (score 0.0056)
CWE
CWE-122
OTX pulses
4 total, 0 recent

source mentions 2

source consensus

  • MSRC Update Guide
  • oss-security
Want the 3-bullet summary of CVE-2026-34355, plus webhook alerts when KEV is updated? Pro is $10/mo.