Apache httpd 2.4.69 fixes 20 flaws, including CVE-2026-63292
Apache HTTP Server 2.4.69 was released on 1 October 2026, fixing twenty security issues in the 2.4 branch. The key one, CVE-2026-63292, is a stack-based buffer overflow in mod_vhost_alias affecting every release from 2.4.0 through 2.4.68; the patch bounds the buffer when expanding the Host header.
- CVE-2026-63292 is a stack buffer overflow in mod_vhost_alias rated moderate
- All Apache httpd versions from 2.4.0 to 2.4.68 are affected
- No config change needed, but reviewing LimitRequestFieldSize is advised
- The release also patches mod_http2, mod_ssl, mod_rewrite and other modules
Read next
Security