kozhevnikoCVE-2026-63292: A Configuration-Dependent Stack Overflow in Apache httpd 2.4 What...
The Apache Software Foundation published CVE-2026-63292 as a stack-based buffer overflow in mod_vhost_alias, fixed in Apache HTTP Server 2.4.69 on 1 October 2026. Apache classifies the defect as moderate and states that all releases from 2.4.0 through 2.4.68 are affected on every platform. The advisory credits Hyojae Lee and Zhen Kong; the issue was reported on 17 June 2026 and fixed in the 2.4.x branch as r1938676.
mod_vhost_alias removes the need for one <VirtualHost> block per hostname. Its VirtualDocumentRoot directive accepts format specifiers, and the hostname-oriented variants derive their value from the incoming Host header. At request time httpd expands that hostname into a filesystem path. The expansion copies the result into a stack buffer with a fixed capacity.
The overflow occurs when the expanded hostname does not fit. Apache's advisory sets three simultaneous requirements:
mod_vhost_alias is loaded.VirtualDocumentRoot uses a hostname format specifier.LimitRequestFieldSize has been raised above its default, allowing a Host header longer than 8192 bytes.
Remove any one of them and the vulnerable path is not reached.Apache httpd caps a single request header field at 8192 bytes by default. That ceiling keeps oversized Host values away from the expansion code. Operators raise LimitRequestFieldSize when legitimate traffic needs long header values: large cookies, bearer tokens, hostnames for internal staging, or metadata passed through a gateway. Each of those raises the ceiling and removes the built-in protection.
The advisory states that a remote client can cause a denial of service or potentially execute arbitrary code. Denial of service is the certain outcome: a stack overflow inside a worker process terminates it, and repeated attempts can exhaust the process pool. Arbitrary code execution is the stated potential outcome, which is what raises the risk above what a moderate rating normally implies for an internet-facing service.
A ZoomEye search for app="Apache httpd" returns 596,254,434 assets worldwide. A CVE-indexed search for vul.cve="CVE-2026-63292" returns zero. The first number measures the size of the Apache httpd footprint; it is not a count of vulnerable servers, and the second number does not prove that none exist.
LimitRequestFieldSize back to 8192.VirtualDocumentRoot for hostname specifiers.mod_vhost_alias when it is not required.Host headers at the edge.