CRITICAL🇵🇱 Wersja polska

CVE-2026-44631

CVSS 9.8v3.1pub. 2026-06-08upd. 2026-06-11

Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

🤖 AI Analysis
How it works

The vulnerability is a buffer underwrite error that can be triggered through specially crafted regular expressions placed in Apache HTTP Server configuration. Writing data below the lower boundary of the allocated memory buffer can lead to corruption of adjacent data structures or code. A network attack vector without requiring authentication or user interaction (AV:N/AC:L/PR:N/UI:N) indicates that the exploit can be executed remotely with low complexity.

Impact

An attacker can gain full control over the server, which includes unauthorized access to sensitive data, data modification, and the ability to cause service unavailability. High impact on confidentiality, integrity, and availability (C:H/I:H/A:H) makes this vulnerability exceptionally dangerous.

Mitigation & patch

Apache HTTP Server must be updated immediately to version 2.4.68, which contains a patch eliminating the described vulnerability. Details available on the vendor's website: https://httpd.apache.org/security/vulnerabilities_24.html

Who is affected

Apache HTTP Server in versions 2.4.0 to 2.4.67 inclusive.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apache HTTP Server

    APP
    Apache
    2.4.0 – 2.4.68 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-38475CRITICAL9.1⚠ KEVPL ✓same product

Apache HTTP Server mod_rewrite — ujawnienie kodu i RCE poprzez błędne escapowanie

CVE-2021-42013CRITICAL9.8⚠ KEVPL ✓same product

Apache HTTP Server 2.4.50 — path traversal i RCE (niewystarczający patch CVE-2021-41773)

CVE-2021-41773CRITICAL9.8⚠ KEVPL ✓same product

Apache HTTP Server 2.4.49 — path traversal i RCE (aktywnie exploitowany)

CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product

SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego

CVE-2026-29167CRITICAL9.8PL ✓same product

Use-after-free w Apache HTTP Server z mod_ldap (CVE-2026-29167)