Sceawere
Vulnerability Detail
CVE-2026-56449UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
mod_proxy_html Out-of-bounds Write
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 1d ago
- Vendor
- Apache Software Foundation
- Product
- Apache HTTP Server
- Attack Type
- CWE-787 Out-of-bounds Write
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-01T17:17:26.733Z",
"pubdate": "2026-10-01T17:17:26.733Z",
"executiveSummary": "An out-of-bounds write vulnerability exists in the mod_proxy_html module of the Apache HTTP Server. This flaw, affecting versions 2.4.0 through 2.4.68, arises during the processing of specifically crafted HTTP response bodies.\nThe vulnerability is classified as an out-of-bounds memory access, which can potentially be leveraged to corrupt memory or cause a denial-of-service state. Successful exploitation typically requires an attacker to exert control over the content returned by a proxied backend server, which is then processed by the affected Apache instance.\nThe impact includes potential service instability, such as application crashes, or the possibility of arbitrary code execution depending on the specific memory layout and the nature of the overflow. The risk is elevated in environments where Apache HTTP Server acts as a reverse proxy for untrusted or partially trusted upstream services. Exploitation does not necessarily require authentication to the proxy server itself, as the trigger occurs during the standard proxying of HTTP response traffic.\nOrganizations utilizing mod_proxy_html should assess their exposure to upstream content injection and prioritize updates to remediated versions of the software.",
"technicalDetails": "The vulnerability resides within the mod_proxy_html component of the Apache HTTP Server, which is responsible for rewriting HTML links and content in proxied HTTP responses. The flaw is triggered when the module attempts to process specially crafted HTML response bodies that lead to an incorrect calculation of memory offsets or buffer boundaries during the rewriting process.\nThe root cause is an improper handling of input buffers during the parsing or transformation phases of mod_proxy_html, resulting in an out-of-bounds write condition. When the module encounters a maliciously structured HTTP response, the logic governing the manipulation of HTML elements may write data beyond the allocated buffer constraints assigned to the proxy request handler.\nThe attack flow proceeds as follows: First, an attacker identifies a target Apache HTTP Server configured with mod_proxy_html acting as a reverse proxy for an upstream server. Second, the attacker influences the upstream server to provide a crafted HTTP response body containing specific HTML structures—such as malformed tags, excessive attribute lengths, or unexpected character encoding sequences—designed to trigger the out-of-bounds condition. Third, as the Apache proxy receives and parses this response, mod_proxy_html performs internal buffer operations to sanitize or modify the HTML. Due to the lack of sufficient boundary validation, the write operation exceeds the intended destination buffer.\nThe technical consequence is memory corruption, which can lead to unpredictable application behavior. Depending on the memory segments being overwritten, an attacker might corrupt internal heap structures, function pointers, or sensitive control data. This can be exploited to achieve a denial-of-service (DoS) by crashing the Apache child process, or in more severe scenarios, potentially redirecting execution flow if critical control data is manipulated.\nThis vulnerability does not require authentication against the proxy server, as the exploitation is triggered by the natural flow of proxying response traffic. The network exposure is limited to systems where mod_proxy_html is actively enabled and parsing external content. The exploit payload is embedded within the HTTP response entity body, making the proxy's role as a man-in-the-middle the primary vector for delivery."
}