Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://httpd.apache.org/security/vulnerabilities_24.html |
|
History
Mon, 08 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue. | |
| Title | Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request` | |
| Weaknesses | CWE-126 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-06-08T15:22:11.809Z
Reserved: 2026-05-05T14:42:10.681Z
Link: CVE-2026-44185
No data.
Status : Received
Published: 2026-06-08T16:16:40.327
Modified: 2026-06-08T16:16:40.327
Link: CVE-2026-44185
No data.
OpenCVE Enrichment
Updated: 2026-06-08T16:30:06Z
Weaknesses