CVE Vulnerabilities

CVE-2026-44631

Buffer Underwrite ('Buffer Underflow')

Published: Jun 08, 2026 | Modified: Jul 23, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.7 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration.

This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.

Users are recommended to upgrade to version 2.4.68, which fixes the issue.

Weakness

The product writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.

Affected Software

NameVendorStart VersionEnd Version
Http_serverApache2.4.0 (including)2.4.68 (excluding)
JBoss Core Services for RHEL 8RedHatjbcs-httpd24-httpd-0:2.4.62-16.el8jbcs*
JBoss Core Services for RHEL 8RedHatjbcs-httpd24-mod_http2-0:2.0.29-13.el8jbcs*
JBoss Core Services for RHEL 8RedHatjbcs-httpd24-mod_jk-0:1.2.50-17.redhat_1.el8jbcs*
JBoss Core Services for RHEL 8RedHatjbcs-httpd24-mod_md-1:2.4.28-19.el8jbcs*
JBoss Core Services for RHEL 8RedHatjbcs-httpd24-mod_proxy_cluster-0:1.3.22-12.el8jbcs*
JBoss Core Services for RHEL 8RedHatjbcs-httpd24-mod_security-0:2.9.6-19.el8jbcs*
Red Hat Enterprise Linux 10RedHathttpd-0:2.4.63-13.el10_2.4*
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHathttpd-0:2.4.63-1.el10_0.4*
Red Hat Enterprise Linux 8RedHathttpd:2.4-8100020260714175253.489197e6*
Red Hat Enterprise Linux 9RedHathttpd-0:2.4.62-13.el9_8.5*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHathttpd-0:2.4.53-11.el9_2.15*
Red Hat Enterprise Linux 9.4 Update Services for SAP SolutionsRedHathttpd-0:2.4.57-11.el9_4.5*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHathttpd-0:2.4.62-4.el9_6.6*
Red Hat Hardened ImagesRedHathttpd-main-2.4.68-1.hum1*
Red Hat Insights proxy 1.5RedHatinsights-proxy/insights-proxy-container-rhel9:1786433656*
Apache2Ubuntudevel*
Apache2Ubuntuesm-infra-legacy/xenial*
Apache2Ubuntuesm-infra/bionic*
Apache2Ubuntuesm-infra/focal*
Apache2Ubuntujammy*
Apache2Ubuntunoble*
Apache2Ubuntuquesting*
Apache2Ubunturesolute*
Apache2Ubuntuupstream*

Potential Mitigations

References