In Apache httpd 2.4.67, a vulnerability in HTTP/2 that does not exclude remote code execution has been fixed.

The release of Apache HTTP Server 2.4.67 features the resolution of 11 vulnerabilities along with several fixes. The most critical vulnerability (CVE-2026-23918) is caused by double free memory in the mod_http2 module and may potentially lead to remote code execution on the server through HTTP/2 protocol manipulation. This vulnerability only manifests in release 2.4.66 and has been assigned a severity level of 8.8 out of 10.

Another vulnerability (CVE-2026-24072) with a severity level of 8.8 exists in the mod_rewrite module, allowing local users di hosting, who have the right to create '.htaccess' files, to read the contents of any files on the system with the privileges of the user under which the httpd process is running.

Vulnerabilità meno gravi:

  • CVE-2026-28780 — a buffer overflow in mod_proxy_ajp, which can be exploited when connecting a proxy to a malicious AJP server. By sending specially crafted AJP messages (Apache JServ Protocol), it is possible to write 4 bytes beyond the allocated buffer.
  • CVE-2026-33523 — vulnerabilità di attacco di splitting delle risposte HTTP sui sistemi frontend-backend (HTTP response splitting), che consente l'inserimento di intestazioni di risposta aggiuntive o la frammentazione delle risposte per infiltrarsi nel contenuto delle risposte elaborate nello stesso flusso tra frontend e backend.
  • CVE-2026-33006 — attacco attraverso canali esterni (analisi dei ritardi) su mod_auth_digest, che consente di bypassare l'autenticazione Digest.
  • CVE-2026-29168 — mancanza di adeguati limiti sulle risorse allocate durante l'elaborazione di una risposta OCSP appositamente formattata in mod_md.
  • CVE-2026-29169 — dereferenziazione di un puntatore nullo nel modulo mod_dav_lock, che può essere sfruttata per provocare un crash del processo server.
  • CVE-2026-33007 — dereferenziazione di un puntatore nullo nel modulo mod_authn_socache, che può essere sfruttata per provocare un crash del processo figlio in configurazioni con proxy caching.
  • CVE-2026-33857 — lettura di un byte dalla memoria al di fuori del buffer allocato nel modulo mod_proxy_ajp.
  • CVE-2026-34032 — lettura dei dati dalla memoria al di fuori del buffer allocato a causa della mancanza di controllo sul carattere nullo finale in mod_proxy_ajp.
  • CVE-2026-34059 — perdita del contenuto della memoria in mod_proxy_ajp.

Inoltre, nella nuova versione sono stati risolti bug non legati alla sicurezza in mod_http2 e mod_md, e sono stati aggiunti nuovi tipi MIME nel file conf/mime.types: vnd.sqlite3, HEIC, HEIF.

Fonte: opennet.ru

Acquista un hosting affidabile per siti con protezione DDoS, server VPS VDS 🔥 Acquista un hosting affidabile per siti con protezione DDoS, server VPS VDS | ProHoster