high CVSS 7.5

CVE-2026-63292·Apache vulnerability

Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

Severity
high
Software
Apache
Fixed in
2.4.69
Published
2026-10-01

Affected versions

From: 2.4.0

Until: 2.4.69

Fixed in: 2.4.69

How to fix this CVE

Upgrade Apache HTTP Server to version 2.4.69 or later to resolve a stack-based buffer overflow in the mod_vhost_alias module. This vulnerability can be triggered when VirtualDocumentRoot uses hostname format specifiers and the LimitRequestFieldSize directive is configured above its default value. Organizations should prioritize this update, particularly if they rely on dynamic virtual host configuration with custom request field size limits.

sudo dnf update httpd

Defensia detects this vulnerability

What an exploitation attempt looks like

Sample log line indicative of exploitation attempts:

POST|GET|HEAD|OPTIONS|PUT|DELETE HTTP/1\.1.*Host: .{8193,}

WAF mitigation (if patching is not yet possible)

Add this rule to your WAF to block exploitation attempts while you schedule the patch.

Implement a WAF rule to reject HTTP requests with Host header values exceeding 8192 bytes. Additionally, if using mod_vhost_alias with format specifiers, restrict requests to known valid hostnames using a whitelist rule before they reach the vulnerable module.

How to check if you are affected

  1. Run 'apache2ctl -v' (Ubuntu/Debian) or 'httpd -v' (RHEL/CentOS) to check the installed Apache version. Versions 2.4.0 through 2.4.68 are vulnerable.
  2. Check your Apache configuration file (typically /etc/apache2/apache2.conf or /etc/httpd/conf/httpd.conf) for the presence of 'VirtualDocumentRoot' directive with hostname format specifiers (e.g., %s or similar placeholders).
  3. Verify the LimitRequestFieldSize setting in your configuration: run 'grep -i LimitRequestFieldSize /etc/apache2/apache2.conf /etc/apache2/conf-enabled/* 2>/dev/null' — if set above 8192, the risk is elevated.
  4. Review Apache error and access logs for unusually large Host header values or malformed HTTP requests: 'grep -i 'host.*' /var/log/apache2/access.log | awk '{print length($0), $0}' | sort -rn | head -20'

FAQ

What is CVE-2026-63292?

CVE-2026-63292 is a stack-based buffer overflow in Apache's mod_vhost_alias module that occurs when processing oversized Host headers in HTTP requests, particularly when VirtualDocumentRoot directives use hostname format specifiers. This can lead to denial of service or arbitrary code execution on affected systems.

Is CVE-2026-63292 being actively exploited?

No, CVE-2026-63292 is not currently listed as actively exploited in the CISA Known Exploited Vulnerabilities catalog, and no public exploits are available. However, organizations should not delay patching given the high severity rating.

What versions of Apache are affected by CVE-2026-63292?

Apache HTTP Server versions 2.4.0 through 2.4.68 are vulnerable. Version 2.4.69 and later contain the fix.

How do I check if my server is vulnerable to CVE-2026-63292?

Run 'httpd -v' or 'apache2ctl -v' and confirm your version is between 2.4.0 and 2.4.68. Additionally, verify that mod_vhost_alias is enabled and VirtualDocumentRoot is configured in your Apache settings.

Does Defensia detect CVE-2026-63292?

Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2026-63292 will appear in your dashboard with remediation steps.

Related Apache CVEs

CVE-2021-41773CVSS 10A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.
CVE-2021-42013CVSS 10It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier versions.
CVE-2024-38474CVSS 9.8Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.
CVE-2026-57941CVSS 9.8Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
CVE-2024-38476CVSS 9.8Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

References

Track CVEs across your fleet automatically

Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-63292. Free for 1 server.

Get started free