Skip to main content
Mallory
Back to intelligence
internet-facing-service-vulnerabilitywidely-deployed-product-advisoryprivilege-escalation-method

Apache HTTP Server 2.4.68 fixes 13 flaws across HTTP/2, proxy, SSL, LDAP, and WebDAV

Updated 5d agoFirst seen Jun 9, 202621 sources

The Apache Software Foundation released Apache HTTP Server 2.4.68 to patch 13 vulnerabilities affecting versions prior to 2.4.68, with many issues spanning 2.4.0 through 2.4.67. The flaws span multiple modules, including mod_http2, mod_proxy_ftp, mod_proxy_html, mod_ssl, mod_ldap, mod_dav_fs, mod_xml2enc, and mod_headers, and include use-after-free, heap and buffer overflows, out-of-bounds reads, denial-of-service conditions, cross-site scripting, privilege-escalation and path-handling weaknesses. Apache and national defenders, including Canada’s Cyber Centre, urged administrators to review the advisory and upgrade because workarounds are unavailable for most of the issues.

Notable CVEs include CVE-2026-49975, a mod_http2 denial-of-service bug triggered by excessive size values in malicious HTTP/2 requests; CVE-2026-48913, a mod_http2 memory-corruption issue when file handles are exhausted; CVE-2026-34355 and CVE-2026-34356, buffer-overflow flaws tied to untrusted backend systems in mod_proxy_html and ProxyPassReverseCookie*; CVE-2026-44631, a heap underflow in ap_regname caused by crafted regular expressions; CVE-2026-29167, a mod_ldap per-directory use-after-free; CVE-2026-29170 and CVE-2026-44186 in mod_proxy_ftp; CVE-2026-44185 in mod_ssl OCSP handling; and CVE-2026-42535 in mod_dav_fs. The release also ships non-security changes such as OpenSSL 4.0 support and mod_http2 updates, but the immediate priority for exposed environments is upgrading all Apache HTTP Server deployments to 2.4.68.

Share:
Apache HTTP Server 2.4.68 fixes 13 flaws across HTTP/2, proxy, SSL, LDAP, and WebDAV
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

14 events from the most recent confirmed update back to the earliest known activity.

14 EVENTS
Jun 8, 20267d ago

Apache releases HTTP Server 2.4.68 with security fixes

Apache released HTTP Server 2.4.68 on June 8, 2026 to fix 13 vulnerabilities affecting multiple modules, including mod_http2, mod_ssl, mod_proxy_ftp, mod_dav_fs, mod_ldap, mod_xml2enc, mod_headers, and mod_proxy_html. Apache advised users running earlier versions to upgrade to remediate the issues.

Apache HTTP Server 2.4.68 Released With Fix For Use-After-Free, DoS, XSS, and Buffer Overflow Flaws
Jun 6, 20269d ago

Debian publishes apache2 security update DSA-6323-1

Debian published security advisory DSA-6323-1 for apache2. The reference indicates a product security update was issued, though no synopsis details are provided in the source content.

[SECURITY] [DSA 6323-1] apache2 security update
Jun 5, 202610d ago

Apache fixes six vulnerabilities in the 2.4.x branch

Apache committed fixes on June 5, 2026 for CVE-2026-34356, CVE-2026-42535, CVE-2026-43951, CVE-2026-44186, and CVE-2026-44631 in the 2.4.x branch. These changes addressed flaws in proxy cookie rewriting, WebDAV path handling, header merging, mod_proxy_ftp looping, and ap_regname heap underflow.

oss-sec: CVE-2026-34356: Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow
Jun 4, 202611d ago

Apache fixes four vulnerabilities in the 2.4.x branch

Apache committed fixes on June 4, 2026 for CVE-2026-34355, CVE-2026-29170, CVE-2026-42536, and CVE-2026-42536's related code revision r1934971. The changes addressed mod_proxy_html overflow, mod_proxy_ftp XSS, and mod_xml2enc heap overflow issues.

oss-sec: CVE-2026-34355: Apache HTTP Server: mod_proxy_html buffer overflow
Jun 3, 202612d ago

Apache fixes two vulnerabilities in the 2.4.x branch

Apache fixed CVE-2026-48913 in revision r1934882 and CVE-2026-44185 in revision r1934919 in the 2.4.x branch. These addressed a mod_http2 memory-corruption issue and a mod_ssl stack buffer over-read.

oss-sec: CVE-2026-48913: Apache HTTP Server: mod_http2 memory corruption when file handles exhausted
Jun 2, 202613d ago

Apache incorporates CVE-2026-49975 fix into 2.4.x

Apache incorporated the previously upstreamed fix for CVE-2026-49975 into the 2.4.x branch. This prepared the HTTP/2 denial-of-service fix for inclusion in the next HTTP Server release.

oss-sec: CVE-2026-49975: Apache HTTP Server: mod_http2 denial of service
May 27, 202619d ago

mod_http2 DoS fix lands upstream

The fix for CVE-2026-49975 was applied upstream in mod_h2. Apache later incorporated that change into the 2.4.x branch before the public release.

oss-sec: CVE-2026-49975: Apache HTTP Server: mod_http2 denial of service
May 26, 202620d ago

Apache receives report for CVE-2026-49975 HTTP/2 DoS

Apache received a report for CVE-2026-49975, a denial-of-service issue caused by excessive size values in the HTTP/2 component. The flaw affects Apache HTTP Server versions 2.4.17 through 2.4.67.

oss-sec: CVE-2026-49975: Apache HTTP Server: mod_http2 denial of service
May 22, 202624d ago

Apache receives report for CVE-2026-48913 mod_http2 corruption

Apache received a report for CVE-2026-48913, a mod_http2 vulnerability that can lead to memory corruption when file handles are exhausted. Apache HTTP Server versions 2.4.55 through 2.4.67 are affected.

oss-sec: CVE-2026-48913: Apache HTTP Server: mod_http2 memory corruption when file handles exhausted
Apr 27, 20262mo ago

Apache receives reports for six April 27 vulnerabilities

Apache received reports on April 27, 2026 for CVE-2026-42535, CVE-2026-42536, CVE-2026-43951, CVE-2026-44185, CVE-2026-44186, and CVE-2026-44631. These issues span mod_dav_fs, mod_xml2enc, mod_headers, mod_ssl, mod_proxy_ftp, and ap_regname, affecting versions through 2.4.67.

oss-security - CVE-2026-42536: Apache HTTP Server: mod_xml2enc heap overflow
Mar 21, 20263mo ago

Apache receives report for CVE-2026-34355 mod_proxy_html overflow

Apache received a report for CVE-2026-34355, a buffer overflow vulnerability in mod_proxy_html that can be triggered by an untrusted backend. The issue affects Apache HTTP Server versions 2.4.0 through 2.4.67.

oss-sec: CVE-2026-34355: Apache HTTP Server: mod_proxy_html buffer overflow
Mar 4, 20263mo ago

Apache receives report for CVE-2026-29170 mod_proxy_ftp XSS

Apache received a report for CVE-2026-29170, a cross-site scripting flaw in mod_proxy_ftp affecting HTML directory list generation for FTP directory contents. Apache HTTP Server 2.4.67 and earlier are affected.

oss-sec: CVE-2026-29170: Apache HTTP Server: mod_proxy_ftp XSS
Mar 2, 20264mo ago

Apache receives report for CVE-2026-29167 mod_ldap use-after-free

Apache received a report for CVE-2026-29167, a use-after-free vulnerability in mod_ldap when used in per-directory configuration. Apache HTTP Server versions 2.4.0 through 2.4.67 are affected.

oss-sec: CVE-2026-29167: Apache HTTP Server: mod_ldap per-dir use-after-free
Feb 23, 20264mo ago

Apache receives report for CVE-2026-34356 buffer overflow

Apache received a report for CVE-2026-34356, a heap-based buffer overflow involving ProxyPassReverseCookie* when interacting with malicious backend servers. The flaw affects Apache HTTP Server versions 2.4.0 through 2.4.67.

oss-sec: CVE-2026-34356: Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Apache HTTP Server 2.4.68 fixes 13 flaws across HTTP/2, proxy, SSL, LDAP, and WebDAV | Mallory