CVE-2026-63292: A Configuration-Dependent Stack Overflow in Apache httpd 2.4
What Apache disclosed
The Apache Software Foundation published CVE-2026-63292 as a stack-based buffer overflow in mod_vhost_alias, fixed in Apache HTTP Server 2.4.69 on 1 October 2026. Apache classifies the defect as moderate and states that all releases from 2.4.0 through 2.4.68 are affected on every platform. The advisory credits Hyojae Lee and Zhen Kong; the issue was reported on 17 June 2026 and fixed in the 2.4.x branch as r1938676.
Where the bug sits
mod_vhost_alias removes the need for one <VirtualHost> block per hostname. Its VirtualDocumentRoot directive accepts format specifiers, and the hostname-oriented variants derive their value from the incoming Host header. At request time httpd expands that hostname into a filesystem path. The expansion copies the result into a stack buffer with a fixed capacity.
The overflow occurs when the expanded hostname does not fit. Apache's advisory sets three simultaneous requirements:
-
mod_vhost_aliasis loaded. -
VirtualDocumentRootuses a hostname format specifier. -
LimitRequestFieldSizehas been raised above its default, allowing aHostheader longer than 8192 bytes. Remove any one of them and the vulnerable path is not reached.
Why the guard is usually off
Apache httpd caps a single request header field at 8192 bytes by default. That ceiling keeps oversized Host values away from the expansion code. Operators raise LimitRequestFieldSize when legitimate traffic needs long header values: large cookies, bearer tokens, hostnames for internal staging, or metadata passed through a gateway. Each of those raises the ceiling and removes the built-in protection.
Consequences
The advisory states that a remote client can cause a denial of service or potentially execute arbitrary code. Denial of service is the certain outcome: a stack overflow inside a worker process terminates it, and repeated attempts can exhaust the process pool. Arbitrary code execution is the stated potential outcome, which is what raises the risk above what a moderate rating normally implies for an internet-facing service.
Scope and uncertainty
- Versions 2.4.0 through 2.4.68.
- All platforms.
- Exploitation additionally requires the module and the two configuration conditions above. Apache's advisory does not report exploitation in the wild and does not reference a public proof-of-concept. Configuration-dependent bugs of this kind often stay quiet because the population of exposed-and-vulnerable hosts is smaller than the population of installed hosts.
ZoomEye view
A ZoomEye search for app="Apache httpd" returns 596,254,434 assets worldwide. A CVE-indexed search for vul.cve="CVE-2026-63292" returns zero. The first number measures the size of the Apache httpd footprint; it is not a count of vulnerable servers, and the second number does not prove that none exist.
What to do
- Patch to 2.4.69.
- If patching must wait, lower
LimitRequestFieldSizeback to 8192. - Audit
VirtualDocumentRootfor hostname specifiers. - Disable
mod_vhost_aliaswhen it is not required. - Filter absurdly long
Hostheaders at the edge. - Monitor for repeated httpd worker crashes.
Top comments (0)