High severity7.3NVD Advisory· Published Jun 8, 2026· Updated Sep 2, 2026
CVE-2026-44185
CVE-2026-44185
Description
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
23cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*range: >=2.4.0,<2.4.68
- (no CPE)range: 2.4.0 - 2.4.67
- osv-coords21 versionspkg:bitnami/apachepkg:rpm/almalinux/httpdpkg:rpm/almalinux/httpd-corepkg:rpm/almalinux/httpd-develpkg:rpm/almalinux/httpd-filesystempkg:rpm/almalinux/httpd-manualpkg:rpm/almalinux/httpd-toolspkg:rpm/almalinux/mod_http2pkg:rpm/almalinux/mod_ldappkg:rpm/almalinux/mod_luapkg:rpm/almalinux/mod_mdpkg:rpm/almalinux/mod_proxy_htmlpkg:rpm/almalinux/mod_sessionpkg:rpm/almalinux/mod_sslpkg:rpm/opensuse/apache2&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/apache2-devel&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/apache2-event&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/apache2-manual&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/apache2-prefork&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/apache2-utils&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/apache2-worker&distro=openSUSE%20Leap%2016.0
>= 2.4.0, < 2.4.68+ 20 more
- (no CPE)range: >= 2.4.0, < 2.4.68
- (no CPE)range: < 2.4.63-13.el10_2.4
- (no CPE)range: < 2.4.63-13.el10_2.4
- (no CPE)range: < 2.4.63-13.el10_2.4
- (no CPE)range: < 2.4.63-13.el10_2.4
- (no CPE)range: < 2.4.63-13.el10_2.4
- (no CPE)range: < 2.4.63-13.el10_2.4
- (no CPE)range: < 1.15.7-10.module_el8.10.0+4233+8b7d9181.7
- (no CPE)range: < 2.4.63-13.el10_2.4
- (no CPE)range: < 2.4.63-13.el10_2.4
- (no CPE)range: < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2
- (no CPE)range: < 1:2.4.63-13.el10_2.4
- (no CPE)range: < 2.4.63-13.el10_2.4
- (no CPE)range: < 1:2.4.63-13.el10_2.4
- (no CPE)range: < 2.4.66-160000.3.1
- (no CPE)range: < 2.4.66-160000.3.1
- (no CPE)range: < 2.4.66-160000.3.1
- (no CPE)range: < 2.4.66-160000.3.1
- (no CPE)range: < 2.4.66-160000.3.1
- (no CPE)range: < 2.4.66-160000.3.1
- (no CPE)range: < 2.4.66-160000.3.1
Patches
Vulnerability mechanics
References
14- www.openwall.com/lists/oss-security/2026/06/08/12nvdMailing ListThird Party Advisory
- httpd.apache.org/security/vulnerabilities_24.htmlnvdVendor Advisory
- access.redhat.com/errata/RHSA-2026:25042nvd
- access.redhat.com/errata/RHSA-2026:34109nvd
- access.redhat.com/errata/RHSA-2026:41906nvd
- access.redhat.com/errata/RHSA-2026:42828nvd
- access.redhat.com/errata/RHSA-2026:47046nvd
- access.redhat.com/errata/RHSA-2026:53371nvd
- access.redhat.com/errata/RHSA-2026:56868nvd
- access.redhat.com/errata/RHSA-2026:56869nvd
- access.redhat.com/errata/RHSA-2026:62165nvd
- access.redhat.com/security/cve/CVE-2026-44185nvd
- bugzilla.redhat.com/show_bug.cginvd
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44185.jsonnvd
News mentions
3- Apache HTTP Server and Answer: 22 Vulnerabilities Disclosed, Including Critical FlawsVypr Intelligence · Jun 10, 2026
- Apache HTTP Server 2.4.68 Released With Fix For Use-After-Free, DoS, XSS, and Buffer Overflow FlawsCyber Security News · Jun 9, 2026
- Apache HTTP Server: 11 Vulnerabilities Disclosed, Including DoS and Memory Corruption FlawsVypr Intelligence · Jun 8, 2026