Out-of-bounds read in Apache HTTP Server - CVE-2026-43951
Published: June 8, 2026
Apache HTTP Server
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in merge_response_headers when processing responses with mod_headers, mod_mime, and multiple response languages. A remote attacker can trigger processing of affected responses to cause a denial of service.
The issue occurs when mod_headers and mod_mime are used with multiple response languages.