CVE-2026-63292: A Configuration-Dependent Stack Overflow in Apache httpd 2.4
CVE-2026-63292: A Configuration-Dependent Stack Overflow in Apache httpd 2.4 What Apache disclosed The Apache Software Foundation published CVE-2026-63292 as a stack-based buffer overflow in mod_vhost_alias, fixed in Apache HTTP Server 2.4.69 on 1 October 2026. Apache classifies the defect as moderate and states that all releases from 2.4.0 through 2.4.68 are affected on every platform. The advisory credits Hyojae Lee and Zhen Kong; the issue was reported on 17 June 2026 and fixed in the 2.4.x branch as r1938676. mod_vhost_alias removes the need for one block per hostname. Its VirtualDocumentR
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in