CVE-2026-29168Patch(apache / http_server)

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache http_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • http_server

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-05); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
http_server

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-05: 1Mentions · 2026-05-12: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-12: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-12: 105-0505-12
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-051
Patch1
2026-05-121
Disclosure1
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Patch

    Apache httpd CVE-2026-29169 "fixed in 2.4.66" was an error https://www.openwall.com/lists/oss-security/2026/05/05/12 2 more (11 total): CVE-2026-29168: mod_md unrestricted OCSP response https://www.openwall.com/lists/oss-security/2026/05/05/6 CVE-2026-28780: Buffer overflow in mod_proxy_ajp via ajp_msg_check_header() https://www.openwall.com/lists/oss-security/2026/05/05/9

    Post summary

    A concise list of three Apache httpd CVEs is provided, noting that CVE-2026-29169 is fixed in version 2.4.66, while the others are referenced by advisory links but no PoC, exploit, or active exploitation details are present.

    00030321
    4.7K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Apache HTTP Server の 5 件の脆弱性が FIX:広大な攻撃範囲を持つ RCE など https://iototsecnews.jp/2026/05/05/critical-apache-http-server-flaw-exposes-millions-of-servers-to-rce-attacks/ 今回の脆弱性の主な原因は、メモリ管理の不備や設定の不備にあります。最も深刻な CVE-2026-23918 は、一度解放されたメモリをプログラムが誤って解放してしまう double-free という現象が HTTP/2 の処理中に発生します。これによりメモリの状態が壊れ、攻撃者に操作される恐れがあります。また CVE-2026-24072 では設定ファイルの評価処理の不備から、本来見えないはずのファイルが読み取られてしまいます。他にも CVE-2026-28780 のような容量制限を超えてデータが書き込まれるバッファ・オーバーフローや、CVE-2026-29168 のリソース割り当て制限の不足、CVE-2026-29169 の NULL ポインタ参照など、プログラムが想定外の挙動をする隙が原因となっています。ご利用のチームは、ご注意ください。 #Apache #CVE202623918 #CVE202624072 #CVE202628780 #CVE202629168 #CVE202629169 #HTTPServer #Vulnerability

    Post summary

    Five Apache HTTP Server vulnerabilities were disclosed, detailing their technical nature and impact, and vendor fixes have been released.

    01000152
    491 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachehttp_server---

Explore more