This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 08 Jun 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 08 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 08 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache http Server |
|
| Vendors & Products |
Apache
Apache http Server |
Mon, 08 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue. | |
| Title | Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request` | |
| Weaknesses | CWE-126 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-06-08T22:32:30.948Z
Reserved: 2026-05-05T14:42:10.681Z
Link: CVE-2026-44185
Updated: 2026-06-08T22:32:30.948Z
Status : Awaiting Analysis
Published: 2026-06-08T16:16:40.327
Modified: 2026-06-09T01:41:00.563
Link: CVE-2026-44185
No data.
OpenCVE Enrichment
Updated: 2026-06-08T20:45:32Z