Description
Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default.
Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Published:
2026-10-01
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://httpd.apache.org/security/vulnerabilities_24.html |
|
History
Thu, 01 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default. Users are recommended to upgrade to version 2.4.69, which fixes this issue. | |
| Title | Apache HTTP Server: mod_vhost_alias stack overflow | |
| Weaknesses | CWE-121 | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-10-01T16:11:47.911Z
Reserved: 2026-07-16T09:06:13.760Z
Link: CVE-2026-63292
No data.
Status : Received
Published: 2026-10-01T17:17:29.803
Modified: 2026-10-01T17:17:29.803
Link: CVE-2026-63292
No data.
OpenCVE Enrichment
No data.
Weaknesses
