PatchesMedium

Apache HTTP Server 2.4.69 fixes 20 flaws across mod_dav, mod_http2 and mod_rewrite

The Apache Software Foundation released httpd 2.4.69 on October 1, closing 20 vulnerabilities. Five are rated moderate, including a stack overflow in mod_vhost_alias reachable through an oversized Host header.

Apache HTTP Server 2.4.69 fixes 20 flaws across mod_dav, mod_http2 and mod_rewrite

At a glance

  • Apache HTTP Server 2.4.69 fixes 20 vulnerabilities, five rated moderate and fifteen low, affecting versions up to and including 2.4.68.
  • The moderate issues sit in mod_vhost_alias, mod_dav, mod_dav_fs, mod_http2 and directory handling on Windows with 8.3 short names.
  • The project says CVE-2026-63292 in mod_vhost_alias can cause a crash or possible code execution via an oversized Host header.
  • No exploitation is reported, and most issues require a specific module to be loaded and configured rather than affecting default builds.

The Apache Software Foundation released Apache HTTP Server 2.4.69 on October 1, closing 20 vulnerabilities in one of the most widely deployed web servers in use. According to the project's own vulnerability listing for the 2.4 branch, five of the issues are rated moderate and the rest low, with affected version ranges reaching back to 2.4.0 in most cases and covering everything up to 2.4.68. There is no report of exploitation, but the affected code includes modules that are routinely enabled on reverse proxies and WebDAV servers, which is reason enough to schedule the upgrade rather than skip it.

What happened

Apache publishes each fixed flaw with a severity rating and an affected range on its security page; the 2.4.69 batch is unusually large for a single release. Cyber Security News, which covered the release on October 2, counts five moderate and fifteen low-severity entries and stresses that the code execution issues come with "important limits" and do not affect default deployments — exploitation generally depends on a specific module being loaded and configured in a particular way.

Technical details

The five moderate entries, per Apache's listing, are:

  • CVE-2026-63292 — a stack overflow in mod_vhost_alias triggered by an oversized Host header. Cyber Security News describes the impact as a "crash or possible code execution." Affects 2.4.0 through 2.4.68.
  • CVE-2026-42528 — a shared lock overflow in mod_dav that crashes the server.
  • CVE-2026-93546 — a namespace overflow in mod_dav_fs reached through a PROPPATCH request carrying many XML namespaces, which Cyber Security News says can lead to crashes and database corruption.
  • CVE-2026-57941 — a use-after-free in mod_http2 caused by re-entrancy on a shared session buffer.
  • CVE-2026-59685 — an out-of-bounds write in ap_directory_walk() on Windows installations where 8.3 short filenames are in play.

The low-severity set covers a wide spread of modules, including a use-after-free in mod_rewrite via %{LA-U:HTTP:...} lookaheads, response smuggling through mod_proxy_uwsgi Transfer-Encoding handling, two mod_auth_digest replay and denial-of-service issues, a heap overflow in mod_charset_lite, information disclosure in mod_userdir via /./ path equivalence, and a mod_dav_fs issue that exposes the property database to plain GET requests.

Who is affected

Any installation running 2.4.68 or earlier, which is to say every 2.4 deployment that has not been updated since the start of October. Exposure in practice depends on the module mix: a plain static-content server loads very little of the affected code, while a reverse proxy using mod_http2 and mod_rewrite, or a WebDAV server running mod_dav and mod_dav_fs, touches several of the moderate issues at once. The Windows ap_directory_walk() flaw only matters where 8.3 short-name generation is enabled.

What to do

Upgrade to 2.4.69, which is the only fix the project offers for this set. Before that, take an inventory of which modules are actually loaded — httpd -M lists them — and prioritise hosts that load mod_dav, mod_dav_fs, mod_http2, mod_vhost_alias or mod_proxy_uwsgi. Unloading a module that is not needed is the one durable mitigation for these classes of bug. Distribution-packaged builds will carry backported fixes on their own schedule, so check the vendor advisory rather than assuming the version string alone tells the story.

Related CVEs

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.