PT-2026-103935 · Apache · Apache Http Server

·

CVE-2026-63292

·

Published

2026-10-01

·

Updated

2026-10-01

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions prior to 2.4.69
Description A stack-based buffer overflow exists in the mod vhost alias module. A remote client can trigger a denial of service or potentially execute arbitrary code by sending an HTTP request with a Host header exceeding 8192 bytes. This occurs when VirtualDocumentRoot uses a hostname format specifier and the LimitRequestFieldSize directive is increased above its default value.
Recommendations Upgrade to version 2.4.69.

Fix

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63292

Affected Products

Apache Http Server