CVE-2026-63292

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 3 mentions on most recent observed day (2026-10-02)
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-10-01: 2Mentions · 2026-10-02: 310-0110-02
Referenced assets4 URLs
Full discourse5 posts
  • Netlas.io@Netlas_io

    CVE-2026-63292 and others: Multiple vulnerabilities in Apache HTTP Server, up to 9.8 rating ‍🔥 Apache Software Foundation disclosed 20 new vulnerabilities. The most severe can lead to RCE, arbitrary code execution via stack-based buffer overflow, and DoS/potential RCE via use-after-free. Memory corruption, privilege escalation, and info disclosure bugs were also patched. 👉 https://nt.ls/fFMkT

    01041269
    7.7K followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    Apache HTTP Server 2.4.69 fixes 20 flaws, including CVE-2026-63292, a mod_vhost_alias stack overflow that may enable code execution. #Apache #ApacheHTTPServer #httpd #CVE202663292 #CVE202657941 #CVE202659685 #PatchNow https://securityonline.info/apache-http-server-2-4-69/

    01022319
    13.0K followersView on X
  • Kazuki Omo@omokazuki

    Apache HTTP Serverの脆弱性(Moderate: CVE-2026-42528, CVE-2026-57941, CVE-2026-59685, CVE-2026-63292, CVE-2026-93546, Low: 複数)と2.4.69リリース #sios_tech #security #vulnerability #セキュリティ #脆弱性 #apache https://security.sios.jp/vulnerability/apache-security-vulnerability-20261002/

    00011105
    374 followersView on X
  • Rıdvan Yağlı@ridvanyagli

    🔴 Apache HTTP Server 2.4.69 yayınlandı. Güncelleme, 2.4.68 ve öncesini etkileyen 20 güvenlik açığını gideriyor. Öne çıkan önemli açıklar: • CVE-2026-63292: mod_vhost_alias — DoS ve koşullu kod çalıştırma • CVE-2026-42356: CGI handler — sınırlı kod çalıştırma • CVE-2026-57941: mod_http2 — UAF / bellek yazma • CVE-2026-93546: mod_dav_fs — crash ve veritabanı bozulması Açıkların çoğu Moderate/Low seviyede ve sömürülebilirlik yapılandırmaya bağlı. Apache 2.4.69'a güncellemeyi düşünün. https://www.apachelounge.com/changelog-2.4.html

    00010152
    2.4K followersView on X
  • VulDB 🛡@vuldb

    We have just added an important vulnerability affecting Apache HTTP Server (CVE-2026-63292) vuldb.​com/vuln/412730

    00001116
    2.3K followersView on X

Explore more