Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
The vulnerability is a buffer underwrite error that can be triggered through specially crafted regular expressions placed in Apache HTTP Server configuration. Writing data below the lower boundary of the allocated memory buffer can lead to corruption of adjacent data structures or code. A network attack vector without requiring authentication or user interaction (AV:N/AC:L/PR:N/UI:N) indicates that the exploit can be executed remotely with low complexity.
An attacker can gain full control over the server, which includes unauthorized access to sensitive data, data modification, and the ability to cause service unavailability. High impact on confidentiality, integrity, and availability (C:H/I:H/A:H) makes this vulnerability exceptionally dangerous.
Apache HTTP Server must be updated immediately to version 2.4.68, which contains a patch eliminating the described vulnerability. Details available on the vendor's website: https://httpd.apache.org/security/vulnerabilities_24.html
Apache HTTP Server in versions 2.4.0 to 2.4.67 inclusive.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache HTTP Server
APPApache2.4.0 – 2.4.68 (excl.)
Related vulnerabilities
Apache HTTP Server mod_rewrite — ujawnienie kodu i RCE poprzez błędne escapowanie
Apache HTTP Server 2.4.50 — path traversal i RCE (niewystarczający patch CVE-2021-41773)
Apache HTTP Server 2.4.49 — path traversal i RCE (aktywnie exploitowany)
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
Use-after-free w Apache HTTP Server z mod_ldap (CVE-2026-29167)