PT-2026-103935 · Apache · Apache Http Server
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions prior to 2.4.69
Description
A stack-based buffer overflow exists in the
mod vhost alias module. A remote client can trigger a denial of service or potentially execute arbitrary code by sending an HTTP request with a Host header exceeding 8192 bytes. This occurs when VirtualDocumentRoot uses a hostname format specifier and the LimitRequestFieldSize directive is increased above its default value.Recommendations
Upgrade to version 2.4.69.
Fix
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Http Server