cbcvebase.
CVE-2021-26691
published 2021-06-10

CVE-2021-26691: In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow

PriorityP270critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
68.07%
99.2th percentile
In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow

Affected

46 ranges· showing 25
VendorProductVersion rangeFixed in
apachehttp_server2.4.0 – 2.4.46
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is in mod_session; specifically triggered by a crafted SessionHeader value sent by an origin server. Monitor for unusually large or malformed SessionHeader values in proxied responses.
  • Only configurations using the 'SessionEnv' directive are vulnerable. Audit httpd configs for presence of SessionEnv to determine exposure.
  • The vulnerable component is mod_session in Apache httpd. Detect exploitation attempts by monitoring for httpd child process crashes when mod_session is loaded.
  • Exploitation can lead to denial of service or arbitrary code execution via a crafted SessionHeader. Alert on unexpected httpd child process terminations (crashes/segfaults) on servers running mod_session.
  • ·Affected Apache HTTP Server versions are 2.4.0 through 2.4.46 inclusive. Versions outside this range are not affected.
  • ·Red Hat Enterprise Linux 8.5.0 shipped a regression (CVE-2021-20325) that re-introduced this vulnerability even after it was fixed in RHEL 8.4. Systems updated to RHEL 8.5.0 should be treated as vulnerable.
  • ·The vulnerability is only exploitable when the SessionEnv directive is enabled, which is not the default configuration.
  • ·The attack vector is network-based and remotely exploitable with no authentication required (CVSS 9.8). The crafted SessionHeader is delivered by an origin server (relevant in reverse-proxy scenarios).

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_msrc9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.