Apache HTTP Server 2.4.68 released, addressing 13 vulnerabilities and several changes.
Resolved vulnerabilities (the first 6 have moderate severity, while the others are low):
- CVE-2026-34355 — buffer overflow in mod_proxy_html, occurring when accessing a backend controlled by an attacker.
- CVE-2026-49975 — denial of service via exhaustion of all available memory for the process.
- CVE-2026-44186 — infinite looping in the mod_proxy_ftp module, exploited when accessing an attacker-controlled FTP server.
- CVE-2026-44119 — local users with rights to create .htaccess files can read the contents of files with httpd user privileges.
- CVE-2026-43951 — process crash from reading outside the allocated buffer in mod_headers and mod_mime.
- CVE-2026-42535 — vulnerability in mod_dav_fs allowing WebDAV content authors to access directories requiring elevated privileges.
- CVE-2026-29167 — use-after-free memory access in mod_ldap.
- CVE-2026-29170 — cross-site scripting in mod_proxy_ftp.
- CVE-2026-34356 — buffer overflow in the implementation of ProxyPassReverseCookieMap.
- CVE-2026-42536 — buffer overflow in mod_xml2enc.
- CVE-2026-44185 — reading from outside the buffer in mod_ssl when making requests to the attacker's OCSP server.
- CVE-2026-44631 — buffer overflow while processing regular expressions in configuration.
- CVE-2026-48913 — use-after-free memory access in mod_http2 occurring when file descriptors are depleted.
Among non-security-related improvements:
- Support for OpenSSL 4.0 has been implemented in mod_ssl and the ab tool.
- mod_ssl has added recognition of the SerialNumber attribute type.
- Support for substitution "%{m}t" for logging time with millisecond precision has been added to the ErrorLogFormat directive.
- mod_http2 module updated to version 2.0.42.
Mənbə: opennet.ru
