CVE-2026-29168

Source
https://cve.org/CVERecord?id=CVE-2026-29168
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-29168.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-29168
Aliases
Downstream
ALPINE (1)
AZL (2)
BELL (1)
CLSA (1)
DEBIAN (1)
MGASA (1)
MINI (1)
OESA (5)
openSUSE (2)
RHSA (8)
RLSA (2)
SUSE (6)
UBUNTU (1)
Related
Published
2026-05-05T13:10:05Z
Modified
2026-08-12T03:30:23Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Apache HTTP Server: mod_md unrestricted OCSP response
Details

Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response data.

This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.

Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Database specific
{
    "cna_assigner":  "apache",
    "cwe_ids":  [
        "CWE-770"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/29xxx/CVE-2026-29168.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "2.4.30"
                },
                {
                    "last_affected":  "2.4.66"
                }
            ],
            "source":  "AFFECTED_FIELD"
        },
        {
            "extracted_events":  [
                {
                    "introduced":  "2.4.30"
                },
                {
                    "fixed":  "2.4.66"
                }
            ],
            "source":  "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/apache/httpd

Affected ranges

Type
GIT
Repo
https://github.com/apache/httpd
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "2.4.30"
        },
        {
            "fixed":  "2.4.66"
        }
    ],
    "source":  "DESCRIPTION"
}

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-29168.json"