← Browse

CVE-2026-34355

Medium

Elevated severity or exploit probability.

CVSS base
7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS — probability of exploitation (30 days)
2.7%
85.0th percentile
CISA KEV
Not listed
Weakness / dates
CWE-120
Published 2026-06-08 · modified 2026-09-14

Description

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

Affected

apache

References

Official: NVD · CVE.org