Stack-based buffer overflow in Apache HTTP Server - CVE-2026-63292
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service or potentially execute arbitrary code.
The vulnerability exists due to a stack-based buffer overflow in mod_vhost_alias when processing an HTTP request with a Host header exceeding 8192 bytes. A remote attacker can send a specially crafted HTTP request to cause a denial of service or potentially execute arbitrary code.
Exploitation requires VirtualDocumentRoot to use a hostname format specifier and LimitRequestFieldSize to be raised above its default value.