Executive brief
Apache HTTP Server is a widely used web server that handles internet traffic and can act as a gateway to other internal servers. A vulnerability exists where a compromised or malicious backend server can send specially crafted data that causes the Apache server to crash or potentially execute unauthorized code. This could lead to service outages or a breach of the server's security if it is configured to rewrite cookies from backend systems.
Technical details
A heap-based buffer overflow (CWE-122) exists in Apache HTTP Server's proxy modules, specifically affecting the ProxyPassReverseCookie, ProxyPassReverseCookieDomain, and ProxyPassReverseCookiePath directives. The vulnerability is triggered when the server processes responses from a malicious or compromised backend server. An attacker controlling a backend server can provide crafted cookie headers that exceed allocated buffer sizes during the header rewriting process. This can result in a denial of service (crash) or potentially remote code execution in the context of the httpd process. The issue is fixed in version 2.4.68.
Affected products
- Apache HTTP Server 2.4.0 through 2.4.67
Timeline
- 2026-02-23: disclosed: Reported to the Apache security team.
- 2026-06-05: patched: Fixed in the 2.4.x development branch.
- 2026-06-08: advisory: Public advisory and version 2.4.68 released.