CVE-2026-29168
7.3Apache Software Foundation · HTTP Server
An allocation of resources without limits or throttling vulnerability in Apache HTTP Server mod_md via OCSP response data allows unauthenticated attackers to impact availability and integrity.
Executive summary
A resource exhaustion vulnerability in Apache HTTP Server versions 2.4.30 through 2.4.66 allows unauthenticated attackers to cause denial of service conditions or unauthorized actions via crafted OCSP response data.
Vulnerability
This issue involves an allocation of resources without limits or throttling vulnerability within the mod_md module via OCSP response data, requiring no authentication.
Business impact
A successful exploit against Apache HTTP Server can lead to partial loss of confidentiality, integrity, and availability, causing potential system downtime and operational disruption. The CVSS score of 7.3 places this issue in the high severity range, reflecting the remote network vector and the absence of required privileges for successful execution.
Remediation
Immediate Action: Upgrade Apache HTTP Server to version 2.4.67 or later where this vulnerability is resolved.
Proactive Monitoring: Monitor server resource utilization such as CPU and memory consumption, alongside HTTP error logs for anomalous requests related to mod_md or OCSP processing.
Compensating Controls: Implement rate limiting and Web Application Firewall rules to inspect and filter incoming OCSP response traffic if immediate patching is not feasible.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Administrators must treat this high severity vulnerability with urgency by scheduling maintenance windows to apply the version 2.4.67 update. Ensuring timely remediation prevents potential resource exhaustion and protects web services from remote exploitation.
More Apache Software Foundation CVEs
Sources
Originally found and disclosed by Pavel Kohout, Aisle Research, Aisle.com, per the CVE Program record.