CVE-2026-63292: A Configuration-Dependent Stack Overflow in Apache httpd 2.4

# apache# httpd# vulnerability# modvhostalias
CVE-2026-63292: A Configuration-Dependent Stack Overflow in Apache httpd 2.4kozhevniko

CVE-2026-63292: A Configuration-Dependent Stack Overflow in Apache httpd 2.4 What...

CVE-2026-63292: A Configuration-Dependent Stack Overflow in Apache httpd 2.4

What Apache disclosed

The Apache Software Foundation published CVE-2026-63292 as a stack-based buffer overflow in mod_vhost_alias, fixed in Apache HTTP Server 2.4.69 on 1 October 2026. Apache classifies the defect as moderate and states that all releases from 2.4.0 through 2.4.68 are affected on every platform. The advisory credits Hyojae Lee and Zhen Kong; the issue was reported on 17 June 2026 and fixed in the 2.4.x branch as r1938676.

Where the bug sits

mod_vhost_alias removes the need for one <VirtualHost> block per hostname. Its VirtualDocumentRoot directive accepts format specifiers, and the hostname-oriented variants derive their value from the incoming Host header. At request time httpd expands that hostname into a filesystem path. The expansion copies the result into a stack buffer with a fixed capacity.
The overflow occurs when the expanded hostname does not fit. Apache's advisory sets three simultaneous requirements:

  1. mod_vhost_alias is loaded.
  2. VirtualDocumentRoot uses a hostname format specifier.
  3. LimitRequestFieldSize has been raised above its default, allowing a Host header longer than 8192 bytes. Remove any one of them and the vulnerable path is not reached.

Why the guard is usually off

Apache httpd caps a single request header field at 8192 bytes by default. That ceiling keeps oversized Host values away from the expansion code. Operators raise LimitRequestFieldSize when legitimate traffic needs long header values: large cookies, bearer tokens, hostnames for internal staging, or metadata passed through a gateway. Each of those raises the ceiling and removes the built-in protection.

Consequences

The advisory states that a remote client can cause a denial of service or potentially execute arbitrary code. Denial of service is the certain outcome: a stack overflow inside a worker process terminates it, and repeated attempts can exhaust the process pool. Arbitrary code execution is the stated potential outcome, which is what raises the risk above what a moderate rating normally implies for an internet-facing service.

Scope and uncertainty

  • Versions 2.4.0 through 2.4.68.
  • All platforms.
  • Exploitation additionally requires the module and the two configuration conditions above. Apache's advisory does not report exploitation in the wild and does not reference a public proof-of-concept. Configuration-dependent bugs of this kind often stay quiet because the population of exposed-and-vulnerable hosts is smaller than the population of installed hosts.

ZoomEye view

A ZoomEye search for app="Apache httpd" returns 596,254,434 assets worldwide. A CVE-indexed search for vul.cve="CVE-2026-63292" returns zero. The first number measures the size of the Apache httpd footprint; it is not a count of vulnerable servers, and the second number does not prove that none exist.

What to do

  • Patch to 2.4.69.
  • If patching must wait, lower LimitRequestFieldSize back to 8192.
  • Audit VirtualDocumentRoot for hostname specifiers.
  • Disable mod_vhost_alias when it is not required.
  • Filter absurdly long Host headers at the edge.
  • Monitor for repeated httpd worker crashes.

Sources