SB2026100189 - Multiple vulnerabilities in Apache HTTP Server



SB2026100189 - Multiple vulnerabilities in Apache HTTP Server

Published: October 1, 2026

Security Bulletin ID SB2026100189
CSH Severity
High
Patch available
YES
Number of vulnerabilities 20
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 10% Medium 55% Low 35%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 20 vulnerabilities.


1) Out-of-bounds write (CVE-ID: CVE-2026-59685)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause memory corruption.

The vulnerability exists due to an out-of-bounds write in the ap_directory_walk() canonical-name rewrite logic when processing paths containing 8.3 names that grow when expanded. A remote attacker can supply a path containing an 8.3 name that expands to cause memory corruption.

The issue occurs on Windows.


2) Information disclosure (CVE-ID: CVE-2026-47360)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper session cookie removal in the mod_session_cookie module when SessionCookieRemove changes across internal redirects. A remote attacker can send a request that triggers an internal redirect to disclose sensitive information.

The session cookie may still be passed to a backend server.


3) Interpretation Conflict (CVE-ID: CVE-2026-42356)

CWE-ID: CWE-436 - Interpretation Conflict

CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to incorrect handler deployment in Apache HTTP Server when processing internal redirects from CGI programs to non-CGI files in CGI-enabled directories. A remote attacker can trigger an internal redirect from a CGI program to execute arbitrary code.

The target file must not have an extension understood by mod_mime.


4) Improper privilege management (CVE-ID: CVE-2026-59797)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to gain unintended privileges.

The vulnerability exists due to improper privilege management in mod_ssl SSLRequire when processing file-related expressions in .htaccess files. A local user can use file-related expressions in an .htaccess file to gain unintended privileges.


5) Improper access control (CVE-ID: CVE-2026-58415)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose WebDAV dead properties of resources they cannot author.

The vulnerability exists due to improper access control in mod_dav_fs when requesting the .DAV state directory through a GET request. A remote attacker can send a GET request for the .DAV state directory to disclose WebDAV dead properties of resources they cannot author.


6) Use-after-free (CVE-ID: CVE-2026-57941)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause memory corruption.

The vulnerability exists due to use-after-free in mod_http2 when re-entering operations involving shared session->bbtmp. A remote attacker can trigger re-entrancy involving shared session->bbtmp to cause memory corruption.


7) Out-of-bounds write (CVE-ID: CVE-2026-56449)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an out-of-bounds write in the mod_proxy_html dump_content component when processing crafted HTTP response bodies. A remote attacker can supply a crafted HTTP response body to cause a denial of service.


8) Use-after-free (CVE-ID: CVE-2026-56154)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in mod_rewrite when using lookahead (%{LA-U:HTTP:...}). A remote attacker can invoke the lookahead functionality to trigger a use-after-free condition.


9) Out-of-bounds write (CVE-ID: CVE-2026-56153)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to write beyond allocated memory.

The vulnerability exists due to an out-of-bounds write in mod_charset_lite's finish_partial_char function when processing crafted input. A remote attacker can provide crafted input to write beyond allocated memory.


10) NULL pointer dereference (CVE-ID: CVE-2026-46729)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a null pointer dereference in mod_heartmonitor when processing traffic received over a unicast listener. A remote attacker can send traffic to the unicast listener to cause a denial of service.


11) Incorrect calculation (CVE-ID: CVE-2026-42528)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to an incorrect memory calculation in mod_dav when creating WebDAV locks. A remote user can create WebDAV locks to cause a denial of service.


12) Integer overflow (CVE-ID: CVE-2026-93546)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service and corrupt a directory's property database.

The vulnerability exists due to an integer overflow in mod_dav_fs when processing PROPPATCH requests declaring many XML namespaces. A remote user can send a crafted PROPPATCH request to cause a denial of service and corrupt a directory's property database.

Write access to WebDAV resources is required.


13) Path traversal (CVE-ID: CVE-2026-79768)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper path canonicalization in the mod_userdir module when handling requests containing a "/./" path. A remote attacker can send a specially crafted request to disclose sensitive information.

Only configurations using an absolute non-wildcard UserDir directive are affected.


14) Inconsistent interpretation of HTTP requests (CVE-ID: CVE-2026-63718)

CWE-ID: CWE-444 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform HTTP response smuggling.

The vulnerability exists due to inconsistent interpretation of HTTP responses in mod_proxy_uwsgi when processing a crafted uwsgi response with a Transfer-Encoding header. A remote attacker can send a crafted uwsgi response to perform HTTP response smuggling.


15) Use-after-free (CVE-ID: CVE-2026-73637)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use-after-free in mod_auth_digest when processing concurrent Digest authentication requests. A remote attacker can send concurrent Digest authentication requests to cause a denial of service.

The issue occurs when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.


16) NULL pointer dereference (CVE-ID: CVE-2026-63686)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a null pointer dereference in mod_xml2enc when processing a proxied response with a charset conversion that partially succeeds and then fails. A remote attacker can provide a specially crafted proxied response to cause a denial of service.


17) Authentication Bypass by Capture-replay (CVE-ID: CVE-2026-73636)

CWE-ID: CWE-294 - Authentication Bypass by Capture-replay

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authentication.

The vulnerability exists due to improper handling of one-time nonces in mod_auth_digest when AuthDigestNonceLifetime is set to 0. A remote attacker can replay captured digest authentication credentials in crafted requests that trigger garbage collection of the client's shared-memory entry to bypass authentication.

Exploitation requires a man-in-the-middle position.


18) Stack-based buffer overflow (CVE-ID: CVE-2026-63292)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service or potentially execute arbitrary code.

The vulnerability exists due to a stack-based buffer overflow in mod_vhost_alias when processing an HTTP request with a Host header exceeding 8192 bytes. A remote attacker can send a specially crafted HTTP request to cause a denial of service or potentially execute arbitrary code.

Exploitation requires VirtualDocumentRoot to use a hostname format specifier and LimitRequestFieldSize to be raised above its default value.


19) Input validation error (CVE-ID: CVE-2026-63045)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause the proxy to open a data connection to an arbitrary third-party host.

The vulnerability exists due to improper input validation in mod_proxy_ftp PASV reply address handling when processing a crafted PASV response from an untrusted FTP server. A remote attacker can send a crafted PASV response to cause the proxy to open a data connection to an arbitrary third-party host.

The issue is limited to forward proxy configurations.


20) Missing Authentication for Critical Function (CVE-ID: CVE-2026-48005)

CWE-ID: CWE-306 - Missing Authentication for Critical Function

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service through forced re-authentication.

The vulnerability exists due to missing authentication checks in mod_auth_digest when processing forged Authorization headers. A remote attacker can send forged Authorization headers to cause a denial of service through forced re-authentication.

Digest authentication must be enabled with AuthDigestNcCheck.


Remediation

Install update from vendor's website.

References