s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2026-29167

📛 CVE Title

Apache HTTP Server: mod_ldap per-dir use-after-free

Description

Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

Description (MITRE) cveawg.mitre.org

Pulled from cveawg.mitre.org/api/cve/CVE-2026-29167 on 2026-07-27. Shown when MITRE's text differs from the cvelistV5 mirror.

Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

Overview

State
Assigner (CNA)
CVSS severity
critical
CVSS score
CVSS 9.8 / 10 9.8 9.8 / 10
CVSS vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Effective score
9.8 / 10 CRITICAL source: CNA overview
MSRC score
8.6 / 10 HIGH MS rating: Important
CWE(s)
CWE-416
Reserved
Published
2026-06-09 07:00 UTC
Last updated
2026-06-20 01:43 UTC
Source
https://www.tenable.com/cve/CVE-2026-29167
Linked Threat
CVE-2026-29167 — CVE-2026-29167

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2026-06-08 16:16:37 UTC
NVD last modified
2026-07-23 07:10:00 UTC
NVD CVSS v3.1
CVSS 9.8 / 10 9.8 9.8 / 10 CRITICAL source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability subscore
3.9 / 10
Impact subscore
5.9 / 10
EPSS score
0.0069 (probability of exploitation in next 30 days)
EPSS percentile
48.95% vs all CVEs — higher = more likely to be exploited, as of 2026-07-26

NVD / KEV / EPSS data refreshed 2026-07-27 00:03 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-35086
Assigner
apache
Published
Jun 8, 2026, 3:07:59 PM
Updated
Jun 9, 2026, 12:31:24 PM
EUVD base score (CVSS 3.1)
9.8 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EUVD-reported EPSS
0.6900
Vendors
Apache Software Foundation
Products
Apache HTTP Server (2.4.0 ≤2.4.67)
Aliases
GHSA-85f4-9pxx-739j

ENISA description: Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

EUVD references (1)

Microsoft Security Response Center MSRC

Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-07-23 03:00 UTC (source: CVRF).

MS severity
Important
MS CVSS base score
8.6 / 10 (temporal 7.9)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H/E:U
Release
2026-Jun

Affected products — CPE 2.3 (1) NVD

NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.

  • cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*

Vendor references (0)

References embedded in the original CVE record by the assigning CNA.

None in the CVE record.

Web references (5)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

NVD-tagged references (3)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Remediations (10)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

  • web:cve.armis.com

    CVE-2026-29167 (Critical, CVSS 9.8). Published 2026 . A use-after-free in Apache HTTP Server's `mod_ldap` module, triggered via per-directory LDAP configuration…

    2026-06-19 02:37 UTC
  • web:cvefinder.io

    CVSS 9.8, critical severity - Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from... Get full vulnerability details, affected versions, exploit code, EPSS score, and mitigation strategies.

    2026-06-19 02:37 UTC
  • web:nvd.nist.gov

    An official website of the United States government Here's how you know

    2026-06-19 02:37 UTC
  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

    2026-06-19 02:37 UTC
  • web:security-tracker.debian.org

    Vulnerable and fixed packages The table below lists information on source packages.

    2026-06-19 02:37 UTC
  • web:vulners.com

    CVE-2026-29167 is a Use After Free vulnerability in Apache HTTP Server when using mod_ldap in per-directory configuration. The issue affects Apache HTTP Server versions 2.4.0 through 2.4.67. The CVSS base score is 9.8 (Network, N), with high impac...

    2026-06-19 02:37 UTC
  • web:www.computerworld.com

    Microsoft says it is considering a patch for a zero-day vulnerability, dubbed YellowKey, that allows attackers with access to a Windows device to bypass Bitlocker encryption protection and read ...

    2026-06-19 02:37 UTC
  • web:www.ionix.io

    Mitigation and recommended actions Immediate action: Upgrade to Apache HTTP Server 2.4.68, released June 8, 2026 , which resolves this vulnerability ( fix committed as revision r1934935 on June 3, 2026 ).

    2026-06-19 02:37 UTC
  • web:www.tenable.com

    Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

    2026-06-19 02:37 UTC
  • web:www.thehackerwire.com

    How severe is CVE-2026-29167 ? What Apache products are affected by CVE-2026-29167 ? How do I fix or mitigate CVE-2026-29167 ? When was CVE-2026-29167 disclosed?

    2026-06-19 02:37 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2026-29167.json.

Not stored.