CVE-2026-29167
CriticalAdvisory
Published 8 Jun 2026In the index since 6 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.8
- base score, highest
- EPSS
- 0.007
- 51st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 58
- of 17,781 indexed, latest versions
- Container images
- 56
- deployed by those charts
- Fix available
- 4 of 4
- affected packages
Apache HTTP Server: mod_ldap per-dir use-after-free
Carried by container images the latest versions of 58 of 17,781 indexed charts deploy, on 56 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| apache2deb | 2.4.41-4ubuntu3.11, 2.4.41-4ubuntu3.12, 2.4.41-4ubuntu3.14, 2.4.41-4ubuntu3.17+17 more | 2.4.41-4ubuntu3.23+esm6, 2.4.52-1ubuntu4.23, 2.4.58-1ubuntu8.15, 2.4.68-1~deb12u1+1 more | 43 |
| apachebitnami | 2.4.54-157, 2.4.65-1, 2.4.68-1, 2.4.68-8 | 2.4.68 | 4 |
| httpdrpm | 2.4.37-43.module+el8.5.0+13806+b30d9eec.1, 2.4.37-56.module+el8.8.0+18758+b3a9c8da.6, 2.4.37-65.module+el8.10.0+23815+1b5e1c66.7, 2.4.57-8.el9+4 more | 0:2.4.37-65.module+el8.10.0+24755+06195b95.10, 0:2.4.62-13.el9_8.6 | 9 |
| mod_http2rpm | 1.15.7-10.module+el8.10.0+23369+11a81384.4 | 0:1.15.7-10.module+el8.10.0+24521+219dcfc5.7 | 1 |
- OSV records
- BIT-apache-2026-29167DEBIAN-CVE-2026-29167UBUNTU-CVE-2026-29167RHSA-2026:59347RHSA-2026:64794
- Also known as
- USN-8516-1, USN-8589-1
Charts affected
58 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| typo3schoolguys-helmcharts | 0.4.2 | 1 of 1See more | 4,836 |
| testing-multitoolsomeblackmagic | 0.1.2 | 1 of 1See more | 30,687 |
| workshop-operatorstakaterVerified publisher | 0.0.38 | 1 of 2See more | 6,671 |
| nagvissvtech-public-helm-charts | 1.0.0 | 1 of 1See more | 9,102 |
| rundecksvtech-public-helm-charts | 1.0.0 | 1 of 2See more | 18,756 |
| nextcloudth-chartsVerified publisher | 0.4.0 | 1 of 1See more | 10,086 |
| owncloudth-chartsVerified publisher | 0.2.1 | 1 of 1See more | 10,006 |
| web-dvwaweb-dvwa | 1.16.0 | 1 of 2See more | 10,001 |
Container images carrying it
56 by charts deploying them
A fixed version is listed for 4 of the 4 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | 5f4572ef6d6f | httpd | 0:2.4.62-13.el9_8.6 | 1 |
| quay.io/ | 3194d46df0f9 | httpd | 0:2.4.62-13.el9_8.6 | 1 |
| quay.io/ | cba71dc08c8a | httpd | 0:2.4.62-13.el9_8.6 | 1 |
| quay.io/ | 3fead5702be7 | httpd mod_http2 | 0:2.4.37-65.module+el8.10.0+24755+06195b95.10 0:1.15.7-10.module+el8.10.0+24521+219dcfc5.7 | 1 |
| quay.io/ | 59fe607dfdf2 | httpd | 0:2.4.62-13.el9_8.6 | 1 |
| registry.gitlab.com/ | d76185d7270d | apache2 | 2.4.68-1~deb12u1 | 1 |