Junglewise Threat Intelligence

CVE-2026-34356: Apache HTTP Server heap overflow in ProxyPassReverseCookie directives

CVE-2026-34356 · Severity: info · CVSS 0 · Published 2026-06-08

Technologies: Apache HTTP Server. Vendors: Apache.

Executive brief

Apache HTTP Server is a widely used web server that handles internet traffic and can act as a gateway to other internal servers. A vulnerability exists where a compromised or malicious backend server can send specially crafted data that causes the Apache server to crash or potentially execute unauthorized code. This could lead to service outages or a breach of the server's security if it is configured to rewrite cookies from backend systems.

Technical details

A heap-based buffer overflow (CWE-122) exists in Apache HTTP Server's proxy modules, specifically affecting the ProxyPassReverseCookie, ProxyPassReverseCookieDomain, and ProxyPassReverseCookiePath directives. The vulnerability is triggered when the server processes responses from a malicious or compromised backend server. An attacker controlling a backend server can provide crafted cookie headers that exceed allocated buffer sizes during the header rewriting process. This can result in a denial of service (crash) or potentially remote code execution in the context of the httpd process. The issue is fixed in version 2.4.68.

Affected products

  • Apache HTTP Server 2.4.0 through 2.4.67

Timeline

  • 2026-02-23: disclosed: Reported to the Apache security team.
  • 2026-06-05: patched: Fixed in the 2.4.x development branch.
  • 2026-06-08: advisory: Public advisory and version 2.4.68 released.

References

Related threats