Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Hyojae Lee

#18723of 57,303
15.6Total CVSS
Vulnerabilities · 2
High
2
PT-2026-103935
7.5
2026-10-01
Apache · Apache Http Server · CVE-2026-63292
**Name of the Vulnerable Software and Affected Versions** Apache HTTP Server versions prior to 2.4.69 **Description** A stack-based buffer overflow exists in the `mod vhost alias` module. A remote client can trigger a denial of service or potentially execute arbitrary code by sending an HTTP request with a `Host` header exceeding 8192 bytes. This occurs when `VirtualDocumentRoot` uses a hostname format specifier and the `LimitRequestFieldSize` directive is increased above its default value. **Recommendations** Upgrade to version 2.4.69.
PT-2026-103940
8.1
2026-10-01
Apache · Apache Http Server · CVE-2026-73636
Authentication bypass by capture-replay in mod auth digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.