CVE-2017-7679: Apache HTTP Server

Critical severity, CVSS 9.8. EPSS: 39.3% chance of exploitation in the next 30 days.

In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header.

Affected products

  • Apache HTTP Server: from 2.2.0, before 2.2.33 (fixed in 2.2.33); from 2.4.0, before 2.4.26 (fixed in 2.4.26)

Published 2017-06-20. Last modified 2026-06-17.