SB2026100189 - Multiple vulnerabilities in Apache HTTP Server
Published: October 1, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 20 vulnerabilities.
1) Out-of-bounds write (CVE-ID: CVE-2026-59685)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in the ap_directory_walk() canonical-name rewrite logic when processing paths containing 8.3 names that grow when expanded. A remote attacker can supply a path containing an 8.3 name that expands to cause memory corruption.
The issue occurs on Windows.
2) Information disclosure (CVE-ID: CVE-2026-47360)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper session cookie removal in the mod_session_cookie module when SessionCookieRemove changes across internal redirects. A remote attacker can send a request that triggers an internal redirect to disclose sensitive information.
The session cookie may still be passed to a backend server.
3) Interpretation Conflict (CVE-ID: CVE-2026-42356)
CWE-ID: CWE-436 - Interpretation Conflict
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to incorrect handler deployment in Apache HTTP Server when processing internal redirects from CGI programs to non-CGI files in CGI-enabled directories. A remote attacker can trigger an internal redirect from a CGI program to execute arbitrary code.
The target file must not have an extension understood by mod_mime.
4) Improper privilege management (CVE-ID: CVE-2026-59797)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to gain unintended privileges.
The vulnerability exists due to improper privilege management in mod_ssl SSLRequire when processing file-related expressions in .htaccess files. A local user can use file-related expressions in an .htaccess file to gain unintended privileges.
5) Improper access control (CVE-ID: CVE-2026-58415)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose WebDAV dead properties of resources they cannot author.
The vulnerability exists due to improper access control in mod_dav_fs when requesting the .DAV state directory through a GET request. A remote attacker can send a GET request for the .DAV state directory to disclose WebDAV dead properties of resources they cannot author.
6) Use-after-free (CVE-ID: CVE-2026-57941)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in mod_http2 when re-entering operations involving shared session->bbtmp. A remote attacker can trigger re-entrancy involving shared session->bbtmp to cause memory corruption.
7) Out-of-bounds write (CVE-ID: CVE-2026-56449)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in the mod_proxy_html dump_content component when processing crafted HTTP response bodies. A remote attacker can supply a crafted HTTP response body to cause a denial of service.
8) Use-after-free (CVE-ID: CVE-2026-56154)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger a use-after-free condition.
The vulnerability exists due to use-after-free in mod_rewrite when using lookahead (%{LA-U:HTTP:...}). A remote attacker can invoke the lookahead functionality to trigger a use-after-free condition.
9) Out-of-bounds write (CVE-ID: CVE-2026-56153)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to write beyond allocated memory.
The vulnerability exists due to an out-of-bounds write in mod_charset_lite's finish_partial_char function when processing crafted input. A remote attacker can provide crafted input to write beyond allocated memory.
10) NULL pointer dereference (CVE-ID: CVE-2026-46729)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in mod_heartmonitor when processing traffic received over a unicast listener. A remote attacker can send traffic to the unicast listener to cause a denial of service.
11) Incorrect calculation (CVE-ID: CVE-2026-42528)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to an incorrect memory calculation in mod_dav when creating WebDAV locks. A remote user can create WebDAV locks to cause a denial of service.
12) Integer overflow (CVE-ID: CVE-2026-93546)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service and corrupt a directory's property database.
The vulnerability exists due to an integer overflow in mod_dav_fs when processing PROPPATCH requests declaring many XML namespaces. A remote user can send a crafted PROPPATCH request to cause a denial of service and corrupt a directory's property database.
Write access to WebDAV resources is required.
13) Path traversal (CVE-ID: CVE-2026-79768)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper path canonicalization in the mod_userdir module when handling requests containing a "/./" path. A remote attacker can send a specially crafted request to disclose sensitive information.
Only configurations using an absolute non-wildcard UserDir directive are affected.
14) Inconsistent interpretation of HTTP requests (CVE-ID: CVE-2026-63718)
CWE-ID: CWE-444 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform HTTP response smuggling.
The vulnerability exists due to inconsistent interpretation of HTTP responses in mod_proxy_uwsgi when processing a crafted uwsgi response with a Transfer-Encoding header. A remote attacker can send a crafted uwsgi response to perform HTTP response smuggling.
15) Use-after-free (CVE-ID: CVE-2026-73637)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in mod_auth_digest when processing concurrent Digest authentication requests. A remote attacker can send concurrent Digest authentication requests to cause a denial of service.
The issue occurs when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.
16) NULL pointer dereference (CVE-ID: CVE-2026-63686)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in mod_xml2enc when processing a proxied response with a charset conversion that partially succeeds and then fails. A remote attacker can provide a specially crafted proxied response to cause a denial of service.
17) Authentication Bypass by Capture-replay (CVE-ID: CVE-2026-73636)
CWE-ID: CWE-294 - Authentication Bypass by Capture-replay
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due to improper handling of one-time nonces in mod_auth_digest when AuthDigestNonceLifetime is set to 0. A remote attacker can replay captured digest authentication credentials in crafted requests that trigger garbage collection of the client's shared-memory entry to bypass authentication.
Exploitation requires a man-in-the-middle position.
18) Stack-based buffer overflow (CVE-ID: CVE-2026-63292)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service or potentially execute arbitrary code.
The vulnerability exists due to a stack-based buffer overflow in mod_vhost_alias when processing an HTTP request with a Host header exceeding 8192 bytes. A remote attacker can send a specially crafted HTTP request to cause a denial of service or potentially execute arbitrary code.
Exploitation requires VirtualDocumentRoot to use a hostname format specifier and LimitRequestFieldSize to be raised above its default value.
19) Input validation error (CVE-ID: CVE-2026-63045)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause the proxy to open a data connection to an arbitrary third-party host.
The vulnerability exists due to improper input validation in mod_proxy_ftp PASV reply address handling when processing a crafted PASV response from an untrusted FTP server. A remote attacker can send a crafted PASV response to cause the proxy to open a data connection to an arbitrary third-party host.
The issue is limited to forward proxy configurations.
20) Missing Authentication for Critical Function (CVE-ID: CVE-2026-48005)
CWE-ID: CWE-306 - Missing Authentication for Critical Function
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service through forced re-authentication.
The vulnerability exists due to missing authentication checks in mod_auth_digest when processing forged Authorization headers. A remote attacker can send forged Authorization headers to cause a denial of service through forced re-authentication.
Digest authentication must be enabled with AuthDigestNcCheck.
Remediation
Install update from vendor's website.
References
- https://lists.apache.org/api/email.lua?id=oqyomf60j1yml29f43mgy7ztdnvt8twc
- https://httpd.apache.org/security/vulnerabilities_24.html
- https://lists.apache.org/api/email.lua?id=ctxwvy1jn00xjv0qkdtzr8nzj0mpld8t
- https://lists.apache.org/api/email.lua?id=pkqpb6ygojghsysobd6kkhg2mj0fp2dk
- https://svn.apache.org/viewvc?view=revision&revision=1938650
- https://lists.apache.org/api/email.lua?id=hqgds2nmsf3rkhwhp5g0b93wwq3jd2c9
- https://svn.apache.org/viewvc?view=revision&revision=1938672
- https://lists.apache.org/api/email.lua?id=4xx7m7ztgcfx25b1141wcq2vslcl16cc
- https://lists.apache.org/api/email.lua?id=k6m4l8yyyglsmlh8j87ozq4nokzvltcs
- https://svn.apache.org/viewvc?view=revision&revision=1938665
- https://lists.apache.org/api/email.lua?id=ps38o3fq6f1rxyp9bw4hfj8vl63q8xwb
- https://lists.apache.org/api/email.lua?id=9z0c7z6kb5dm7t2h3fwdy4jd8d9xl6ng
- https://lists.apache.org/api/email.lua?id=jn3mdwj30cf13v3fsxoxmp4vhn1zmw86
- https://svn.apache.org/viewvc?view=revision&revision=1938658
- https://lists.apache.org/api/email.lua?id=3zpv62pr2fd45dddycb01gt6571qk8p9
- https://lists.apache.org/api/email.lua?id=g5hbosqkq8l2hcqqnqmmsky95h69n865
- https://lists.apache.org/api/email.lua?id=mjwl5gxgslkfv971r9hl604oqhtv7kfj
- https://lists.apache.org/api/email.lua?id=63wmzs4y1p3mjo7t8cqwjp8kdt65x055
- https://lists.apache.org/api/email.lua?id=75octch0556n7mr3ctcs3q7zw5rs79kk
- https://svn.apache.org/viewvc?view=revision&revision=1938691
- https://lists.apache.org/api/email.lua?id=1dwsbxvc8gcxglqz9dt9oyqdqr12tmcd
- https://lists.apache.org/api/email.lua?id=tf9vz8r789bdblk543h2qdwsq5l92sbm
- https://lists.apache.org/api/email.lua?id=dv9ny5o63d6jnnv40wvtk3rc4b7gkjl0
- https://lists.apache.org/api/email.lua?id=483gtdzpsf4yz4v0tyb64703pt9kllh8
- https://svn.apache.org/viewvc?view=revision&revision=1938676
- https://lists.apache.org/api/email.lua?id=61obl7l634zm9p0dklxzc9c859pkbygd
- https://lists.apache.org/api/email.lua?id=hx0rr3krc95q494ccjb2588jrp1xmqtp