Apache fixes CVE-2026-63292 in httpd 2.4.69: stack overflow in mod_vhost_alias
The Apache Software Foundation released HTTP Server 2.4.69, patching CVE-2026-63292, a stack-based buffer overflow in mod_vhost_alias. All releases from 2.4.0 through 2.4.68 on every platform are affected, but exploitation requires the module loaded, a hostname format specifier in VirtualDocumentRoot, and LimitRequestFieldSize raised above 8192 bytes.
- All Apache httpd versions from 2.4.0 through 2.4.68 on all platforms are affected
- Exploitation needs mod_vhost_alias, a hostname specifier and LimitRequestFieldSize above 8192 bytes
- Apache rates it moderate: denial of service and potentially arbitrary code execution
- The fix shipped in release 2.4.69 on 1 October 2026 (r1938676)
Read next
Security