CVE-2026-29168

CVE-2026-29168: Apache HTTP Server: mod_md unrestricted OCSP response

Vendor Apache Software Foundation
Product Apache HTTP Server
Weakness CWE-770 · Uncontrolled resource consumption
Published May 5, 2026
Last update May 5, 2026

CVSS base score

What the vulnerability does

Description

Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Key dates

Disclosure timeline

May 5, 2026 CVE published
May 5, 2026 Record updated