CVE-2026-42536

Apache HTTP Server vulnerabilities

Beschreibung

Heap-basierte Pufferüberlauf-Schwachstelle im Apache HTTP-Server mit mod_xml2enc, xml2StartParse und nicht vertrauenswürdigem Inhalt Dieses Problem betrifft den Apache HTTP-Server: von Version 2.4.0 bis 2.4.67. Es wird empfohlen, auf Version 2.4.68 zu aktualisieren, die das Problem behebt.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.5
Quelle: nvd-v3
61.5 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
1.0 %
Moderat — Modell schätzt 1-10 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-07-20 19:03 UTC
CWE-122

Weakness-Klassen (CWE)

  • CWE-122Variant

    Heap-based Buffer Overflow

    A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-10 13:20 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/42xxx/CVE-2026-42536.json">CVE-2026-42536</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:66323
  2. CVE Modified2026-08-11 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:53371
    • Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8 (+5)Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8 (+6)
  3. CVE Modified2026-08-10 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8 (+4)Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8 (+5)
  4. CVE Modified2026-07-28 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:47046
    • Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 (+3)Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8 (+4)
  5. CVE Translated2026-07-23 07:10 UTC· nvd@nist.gov
    • Translation: Title: Apache HTTP Server, Description: Vulnerabilidad de desbordamiento de búfer basado en montículo en Servidor HTTP Apache con mod_xml2enc, xml2StartParse y contenido no confiable Este problema afecta a Servidor HTTP Apache: desde 2.4.0 hasta 2.4.67. Se recomienda a los usuarios actualizar a la versión 2.4.68, que corrige el problema.

Betroffene Betriebssysteme

  • linux

    debian / debian_linux11.0

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • apache

    http_server2.4.0 – 2.4.68

  • bitnami

    apache2.4.0

  • bitnami

    apache2.4.17

  • bitnami

    apache2.4.55

  • bitnami

    apache

Quellen & Referenzen

Verknüpfte CVEs

Verknüpfte Empfehlungen

IDCVE-2026-42536