← Back to browse · API

CVE-2026-49975

Severity
HIGH
CVSS
7.5
EPSS
0.27984
Risk score
39.79
CISA KEV
No
PoC
Yes
Published
2026-06-08
Modified
2026-08-05
First seen
2026-08-05
Aliases
CNVD-2026-23633, EUVD-2026-35105, GHSA-262V-G5H9-6MC6
Products
Apache Apache HTTP Server >=2.4.17,<=2.4.67, Apache Software Foundation:Apache HTTP Server 2.4.17 ≤2.4.67, apache:http_server, debian, debian:debian_linux, linux, redhat, suse, ubuntu
Sources
cnvd CNVD-2026-23633
packetstorm 472ea0dfdf38fea59aae282e|CVE-2026-49975
packetstorm 0b29217f742a882945dcd95b|CVE-2026-49975
packetstorm 6ed36f584bdbf7e8f0001469|CVE-2026-49975
euvd EUVD-2026-35105
packetstorm 243c09694bf6f85c0faabe3b|CVE-2026-49975
packetstorm 9ca64d845bb860e57d74552e|CVE-2026-49975
packetstorm 328e9981956b928cab28887e|CVE-2026-49975
packetstorm 0ac602bd74adc35f3ab04c98|CVE-2026-49975
nvd CVE-2026-49975
packetstorm 3783065fccaeaaa67968a6ff|CVE-2026-49975
packetstorm 9e25a38c6915c93534448b4a|CVE-2026-49975
packetstorm 80eb58bef12a50007c91e31c|CVE-2026-49975
packetstorm e6b6cb09b4f8a36fcd4acdca|CVE-2026-49975
packetstorm dae67b2cd5550f45873cc5c6|CVE-2026-49975

Description

Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.

References