CVE-2026-29167 — apache
CVE-2026-29167 is a Use After Free vulnerability in apache. A fix is available for apache — see the affected versions and patch details below.
Apache HTTP Server: mod_ldap per-dir use-after-free
Exploitation Status
No confirmed exploitation observed yet
- CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.
- A successful exploit gives an attacker total control of the affected component, not partial access.
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for CVE-2026-29167.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
Real-World Exposure
apacheReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Bitnami packages — download data is not available via public APIs for these ecosystems.
Description
Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 📦Bitnami | apache | ≥ 2.4.0&&< 2.4.68 | 2.4.68 |
Affected Products
http serverapacheDetection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for apache, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update apache to 2.4.68 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-29167 is resolved across your whole dependency graph.
Workarounds
Constrain what reaches the vulnerable code: limit the size and shape of untrusted input, isolate the affected component in a sandboxed or least-privileged process, and enable the platform's memory-safety mitigations (ASLR, stack protector, hardened allocator) so an out-of-bounds access is more likely to fail closed than to be exploitable.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
CISA's 9.8 is a mechanical worst-case UAF score. Their vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — they're treating it as: "network-facing service, memory corruption primitive, assume RCE." This is how CISA-ADP routinely scores any UAF in a network daemon. They don't analyze actual exploitability; they score the…
upgrade apache web server to 2.4.68Source: Red Hat security advisory for CVE-2026-29167 (CC BY 4.0)
| Product | Fixed in | Advisory |
|---|---|---|
| JBoss Core Services for RHEL 8 | jbcs-httpd24-httpd-0:2.4.62-16.el8jbcs | RHSA-2026:56868 |
| Red Hat Enterprise Linux 10 | httpd-0:2.4.63-13.el10_2.6 | RHSA-2026:60004 |
| Red Hat Enterprise Linux 8 | httpd:2.4-8100020260825093947.489197e6 | RHSA-2026:64794 |
| Red Hat Enterprise Linux 9 | httpd-0:2.4.62-13.el9_8.6 | RHSA-2026:59347 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | httpd-0:2.4.53-11.el9_2.15 | RHSA-2026:67152 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | httpd-0:2.4.57-11.el9_4.5 | RHSA-2026:66323 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | httpd-0:2.4.62-4.el9_6.6 | RHSA-2026:62165 |
| Red Hat JBoss Core Services 2.4.62.SP5 | jbcs-httpd24-httpd | RHSA-2026:56869 |
Frequently Asked Questions
Is CVE-2026-29167 in your dependencies?
Find it across Bitnami, including transitive dependencies.