A notice published on October 1, 2026 describes an out-of-bounds write in Apache HTTP Server for Windows, rated moderate and affecting versions 2.4.0 through 2.4.68.
A security notice published on October 1, 2026 reports CVE-2026-59685, an out-of-bounds write vulnerability in Apache HTTP Server for Windows. It may occur while processing paths with 8.3 names that grow during expansion. The stated severity is moderate; affected versions range from 2.4.0 through 2.4.68.
The text is an automatic translation of material posted to the oss-sec feed. To verify the record, consult the original notice in the feed archive and compare the CVE identifier, affected versions, and description; do not infer fixes or mitigations that the notice does not state. If you use AI to analyze the material, avoid including internal paths, configurations, or other confidential organizational data.