Out-of-bounds Write Vulnerability in Apache HTTP Server's mod_proxy_html
CVE-2026-56449

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
1 October 2026

What is CVE-2026-56449?

An out-of-bounds write vulnerability exists in the mod_proxy_html module of the Apache HTTP Server. This issue can be exploited by sending specially crafted HTTP response bodies, leading to potential data corruption or unauthorized access. The vulnerability may impact the stability and security of systems running affected versions of the server.

Affected Version(s)

Apache HTTP Server 2.4.0 <= 2.4.68

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lucian Nitescu
.