CVE-2026-42536
published 2026-06-08CVE-2026-42536: Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.02%
61.3th percentile
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.4.0 < 2.4.68 | 2.4.68 |
| apache | httpd | — | — |
| apache_software_foundation | apache_http_server | 2.4.0 – 2.4.67 | — |
| ubuntu | apache2 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_ubuntu9.8CRITICAL
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 5.3
CVE-2026-34032 [MEDIUM] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server
incorrectly handled certain memory operations in mod_authn_socache. A
remote attacker could possibly use this issue to cause a denial of service.
(CVE-2026-33007)
Haruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache
HTTP Server had an HTTP response splitting vulnerability in multiple
modules when used with untrusted or compromised backend servers. An
attacker could possibly use this issue to inject arbitrary HTTP headers.
(CVE-2026-33523)
Elhanan Haenel discovered that Apache HTTP Server incorrectly handled
certain memory operations in mod_proxy_ajp. A remote attacker could
possibly use this i
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-07-08·CVSS 9.8
CVE-2026-44119 [CRITICAL] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
It was discovered that Apache HTTP Server's mod_ldap module incorrectly
handled memory when processing per-directory configurations. An attacker
could use this issue to cause the server to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2026-29167)
It was discovered that Apache HTTP Server's mod_proxy_ftp module
incorrectly handled HTML generation for FTP directory listings. A remote
attacker could possibly use this issue to inject arbitrary web script or
HTML. (CVE-2026-29170)
It was discovered that Apache HTTP Server's mod_proxy_html module
incorrectly handled certain content from an untrusted backend. A remote
attacker could possibly use this
Red Hat
httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc
vendor_redhat·2026-06-08·CVSS 7.5
CVE-2026-42536 [HIGH] CWE-120 httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc
httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
A flaw was found in Apache HTTP Server, specifically within the mod_xml2enc module. This heap-based buffer overflow vulnerability can be triggered when processing untrusted content through the xml2StartParse function. A remote attacker could potentially exploit this to cause a denial of service, information disclosure, or possibly arbitrary code execution.
Statement: In Red Hat Enterprise Linux (RHEL), the httpd package includes mod_xml2enc,
VulDB
Apache HTTP Server up to 2.4.67 mod_xml2enc heap-based overflow (EUVD-2026-35100 / Nessus ID 319665)
vuldb·2026-06-09·CVSS 7.5
CVE-2026-42536 [HIGH] Apache HTTP Server up to 2.4.67 mod_xml2enc heap-based overflow (EUVD-2026-35100 / Nessus ID 319665)
A vulnerability categorized as critical has been discovered in Apache HTTP Server up to 2.4.67. This impacts an unknown function of the component mod_xml2enc. Executing a manipulation can lead to heap-based buffer overflow.
This vulnerability is tracked as CVE-2026-42536. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
GHSA
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
ghsa_unreviewed·2026-06-08
CVE-2026-42536 [HIGH] CWE-122 Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-42536 httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc [fedora-all]
bugzilla·2026-06-18·CVSS 7.5
CVE-2026-42536 [HIGH] CVE-2026-42536 httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc [fedora-all]
CVE-2026-42536 httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-42536 httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc
bugzilla·2026-06-08·CVSS 7.5
CVE-2026-42536 [HIGH] CVE-2026-42536 httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc
CVE-2026-42536 httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
https://httpd.apache.org/security/vulnerabilities_24.htmlhttp://www.openwall.com/lists/oss-security/2026/06/08/9https://access.redhat.com/errata/RHSA-2026:25042https://access.redhat.com/errata/RHSA-2026:34109https://access.redhat.com/errata/RHSA-2026:41906https://access.redhat.com/errata/RHSA-2026:42828https://access.redhat.com/errata/RHSA-2026:47046https://access.redhat.com/errata/RHSA-2026:53371https://access.redhat.com/errata/RHSA-2026:56868https://access.redhat.com/errata/RHSA-2026:56869https://access.redhat.com/errata/RHSA-2026:62165https://access.redhat.com/security/cve/CVE-2026-42536https://bugzilla.redhat.com/show_bug.cgi?id=2486411https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42536.json
2026-06-08
Published