CVE-2026-29168: exploitation status and patch state
CVE-2026-29168 · CVSS 7.3 HIGH · patch available
Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data.
This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Is CVE-2026-29168 exploited?
Not in the CISA KEV catalog.
Public exploit code: none found in monitored sources.