CVE-2026-63292: Apache HTTP Server stack overflow risk
A bulletin published on October 1, 2026 reports a moderate-severity flaw in mod_vhost_alias: in affected configurations, a Host header over 8192 bytes may cause denial of service or potentially code execution.
A security bulletin published on October 1, 2026 reports CVE-2026-63292 in Apache HTTP Server's mod_vhost_alias. The text describes a stack-based buffer overflow, rated moderate, that may allow denial of service or possible code execution through an HTTP request with a Host header larger than 8192 bytes. It lists versions 2.4.0 through 2.4.68 on all platforms as affected, under a specific condition: VirtualDocumentRoot uses a hostname-format specifier.
The supplied material is an automatic translation and ends mid-description; it does not provide the remaining conditions or identify a fix. Consult the original oss-sec notice and official Apache information to confirm scope, fix status, and recommended action before proceeding. If you use AI to study logs or configurations, apply your organization's data policy before processing and avoid sending sensitive content without authorization.