OCTOBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-63292

HIGH · CVSS 7.5 EPSS 0.58%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-05

CyberRota Analysis

AI-Generated

The Apache HTTP Server's mod_vhost_alias is vulnerable to a stack-based buffer overflow due to excessive Host header sizes, which can lead to denial of service or arbitrary code execution. This issue affects all platforms running versions up to 2.4.68, particularly when the VirtualDocumentRoot is configured with a hostname format specifier and the LimitRequestFieldSize is increased. Organizations using affected versions should prioritize upgrading to version 2.4.69 to mitigate these risks.

CVE
CVE-2026-63292
Severity
HIGH
CVSS
7.5
EPSS
0.58%
Apache

Original NVD Description

Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)