apache http-server CVE-2026-29167 is a vulnerability in Apache HTTP Server
Published on June 8, 2026

Apache HTTP Server: mod_ldap per-dir use-after-free
Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

Vendor Advisory NVD

Timeline

reported

fixed in 2.4.x by r1934935 93 days later.

2.4.68 released 5 days later.

Weakness Type

What is a Dangling pointer Vulnerability?

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

CVE-2026-29167 has been classified to as a Dangling pointer vulnerability or weakness.


Products Associated with CVE-2026-29167

Want to know whenever a new CVE is published for Apache HTTP Server? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache HTTP Server: