CVE-2026-29167
📛 CVE Title
Apache HTTP Server: mod_ldap per-dir use-after-free
Description
Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Description (MITRE) cveawg.mitre.org
Pulled from cveawg.mitre.org/api/cve/CVE-2026-29167 on 2026-07-27. Shown when MITRE's text differs from the cvelistV5 mirror.
Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- critical
- CVSS score
- 9.8 / 10
- CVSS vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Effective score
- 9.8 / 10 CRITICAL source: CNA overview
- MSRC score
- 8.6 / 10 HIGH MS rating: Important
- CWE(s)
-
CWE-416 - Reserved
- —
- Published
- 2026-06-09 07:00 UTC
- Last updated
- 2026-06-20 01:43 UTC
- Source
- https://www.tenable.com/cve/CVE-2026-29167
- Linked Threat
- CVE-2026-29167 — CVE-2026-29167
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-06-08 16:16:37 UTC
- NVD last modified
- 2026-07-23 07:10:00 UTC
- NVD CVSS v3.1
- 9.8 / 10 CRITICAL source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Exploitability subscore
- 3.9 / 10
- Impact subscore
- 5.9 / 10
- EPSS score
- 0.0069 (probability of exploitation in next 30 days)
- EPSS percentile
- 48.95% vs all CVEs — higher = more likely to be exploited, as of 2026-07-26
NVD / KEV / EPSS data refreshed 2026-07-27 00:03 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-35086 - Assigner
- apache
- Published
- Jun 8, 2026, 3:07:59 PM
- Updated
- Jun 9, 2026, 12:31:24 PM
- EUVD base score (CVSS 3.1)
-
9.8 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EUVD-reported EPSS
- 0.6900
- Vendors
- Apache Software Foundation
- Products
-
Apache HTTP Server (2.4.0 ≤2.4.67)
- Aliases
-
GHSA-85f4-9pxx-739j
ENISA description: Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
EUVD references (1)
Microsoft Security Response Center MSRC
Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-07-23 03:00 UTC (source: CVRF).
- MS severity
- Important
- MS CVSS base score
- 8.6 / 10 (temporal 7.9)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H/E:U - Release
- 2026-Jun
Affected products — CPE 2.3 (1) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (5)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- MSRC update guide: CVE-2026-29167 msrc
- http://www.openwall.com/lists/oss-security/2026/06/08/4 tenable:www.openwall.com
- https://httpd.apache.org/security/vulnerabilities_24.html tenable:httpd.apache.org
- https://nvd.nist.gov/vuln/detail/CVE-2026-29167 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-29167 tenable:www.cve.org
NVD-tagged references (3)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- http://www.openwall.com/lists/oss-security/2026/06/08/4 af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2026/06/09/1 af854a3a-2127-422b-91ae-364da2661108 Mailing List
- https://httpd.apache.org/security/vulnerabilities_24.html security@apache.org Vendor Advisory
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:cve.armis.com
CVE-2026-29167 (Critical, CVSS 9.8). Published 2026 . A use-after-free in Apache HTTP Server's `mod_ldap` module, triggered via per-directory LDAP configuration…
2026-06-19 02:37 UTC -
web:cvefinder.io
CVSS 9.8, critical severity - Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from... Get full vulnerability details, affected versions, exploit code, EPSS score, and mitigation strategies.
2026-06-19 02:37 UTC -
web:nvd.nist.gov
An official website of the United States government Here's how you know
2026-06-19 02:37 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-06-19 02:37 UTC -
web:security-tracker.debian.org
Vulnerable and fixed packages The table below lists information on source packages.
2026-06-19 02:37 UTC -
web:vulners.com
CVE-2026-29167 is a Use After Free vulnerability in Apache HTTP Server when using mod_ldap in per-directory configuration. The issue affects Apache HTTP Server versions 2.4.0 through 2.4.67. The CVSS base score is 9.8 (Network, N), with high impac...
2026-06-19 02:37 UTC -
web:www.computerworld.com
Microsoft says it is considering a patch for a zero-day vulnerability, dubbed YellowKey, that allows attackers with access to a Windows device to bypass Bitlocker encryption protection and read ...
2026-06-19 02:37 UTC -
web:www.ionix.io
Mitigation and recommended actions Immediate action: Upgrade to Apache HTTP Server 2.4.68, released June 8, 2026 , which resolves this vulnerability ( fix committed as revision r1934935 on June 3, 2026 ).
2026-06-19 02:37 UTC -
web:www.tenable.com
Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
2026-06-19 02:37 UTC -
web:www.thehackerwire.com
How severe is CVE-2026-29167 ? What Apache products are affected by CVE-2026-29167 ? How do I fix or mitigate CVE-2026-29167 ? When was CVE-2026-29167 disclosed?
2026-06-19 02:37 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.