Apache Software Foundation Apache HTTP Server, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
The CVSS severity warrants an early asset and exposure review.