Out-of-bounds write in Apache HTTP Server - CVE-2026-59685
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in the ap_directory_walk() canonical-name rewrite logic when processing paths containing 8.3 names that grow when expanded. A remote attacker can supply a path containing an 8.3 name that expands to cause memory corruption.
The issue occurs on Windows.