CVE-2026-63292·Apache vulnerability
Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
- Severity
- high
- Software
- Apache
- Fixed in
- 2.4.69
- Published
- 2026-10-01
Affected versions
From: 2.4.0
Until: 2.4.69
Fixed in: 2.4.69
How to fix this CVE
Upgrade Apache HTTP Server to version 2.4.69 or later to resolve a stack-based buffer overflow in the mod_vhost_alias module. This vulnerability can be triggered when VirtualDocumentRoot uses hostname format specifiers and the LimitRequestFieldSize directive is configured above its default value. Organizations should prioritize this update, particularly if they rely on dynamic virtual host configuration with custom request field size limits.
sudo dnf update httpdDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST|GET|HEAD|OPTIONS|PUT|DELETE HTTP/1\.1.*Host: .{8193,}WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement a WAF rule to reject HTTP requests with Host header values exceeding 8192 bytes. Additionally, if using mod_vhost_alias with format specifiers, restrict requests to known valid hostnames using a whitelist rule before they reach the vulnerable module.How to check if you are affected
- Run 'apache2ctl -v' (Ubuntu/Debian) or 'httpd -v' (RHEL/CentOS) to check the installed Apache version. Versions 2.4.0 through 2.4.68 are vulnerable.
- Check your Apache configuration file (typically /etc/apache2/apache2.conf or /etc/httpd/conf/httpd.conf) for the presence of 'VirtualDocumentRoot' directive with hostname format specifiers (e.g., %s or similar placeholders).
- Verify the LimitRequestFieldSize setting in your configuration: run 'grep -i LimitRequestFieldSize /etc/apache2/apache2.conf /etc/apache2/conf-enabled/* 2>/dev/null' — if set above 8192, the risk is elevated.
- Review Apache error and access logs for unusually large Host header values or malformed HTTP requests: 'grep -i 'host.*' /var/log/apache2/access.log | awk '{print length($0), $0}' | sort -rn | head -20'
FAQ
What is CVE-2026-63292?
CVE-2026-63292 is a stack-based buffer overflow in Apache's mod_vhost_alias module that occurs when processing oversized Host headers in HTTP requests, particularly when VirtualDocumentRoot directives use hostname format specifiers. This can lead to denial of service or arbitrary code execution on affected systems.
Is CVE-2026-63292 being actively exploited?
No, CVE-2026-63292 is not currently listed as actively exploited in the CISA Known Exploited Vulnerabilities catalog, and no public exploits are available. However, organizations should not delay patching given the high severity rating.
What versions of Apache are affected by CVE-2026-63292?
Apache HTTP Server versions 2.4.0 through 2.4.68 are vulnerable. Version 2.4.69 and later contain the fix.
How do I check if my server is vulnerable to CVE-2026-63292?
Run 'httpd -v' or 'apache2ctl -v' and confirm your version is between 2.4.0 and 2.4.68. Additionally, verify that mod_vhost_alias is enabled and VirtualDocumentRoot is configured in your Apache settings.
Does Defensia detect CVE-2026-63292?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2026-63292 will appear in your dashboard with remediation steps.
Related Apache CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-63292. Free for 1 server.
Get started free