CVE-2026-49975
EUVD-2026-3510508.06.2026, 16:16
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | http_server | 2.4.17 ≤ 𝑥 < 2.4.68 |
| debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | JBoss Core Services for RHEL 8 | 0:2.4.62-13.el8jbcs ≤ 𝑥 < * | ADP |
| Red Hat | JBoss Core Services for RHEL 8 | 0:2.0.29-10.el8jbcs ≤ 𝑥 < * | ADP |
| Red Hat | JBoss Core Services on RHEL 7 | 0:2.4.62-13.el7jbcs ≤ 𝑥 < * | ADP |
| Red Hat | JBoss Core Services on RHEL 7 | 0:2.0.29-10.el7jbcs ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 10 | 0:2.0.29-4.el10_2.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8 | 8100020260608081321.489197e6 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 8040020260702193120.522a0ee4 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | 8040020260702193120.522a0ee4 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 8060020260702195216.ad008a3a ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | 8060020260702195216.ad008a3a ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 8080020260702200145.63b34585 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 8080020260702200145.63b34585 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9 | 0:2.0.26-6.el9_8.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat JBoss Core Services 2.4.62.SP4 | httpd24-httpd ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat JBoss Core Services 2.4.62.SP4 | httpd24-mod_http2 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Hardened Images | 2.4.68-1.hum1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Service Mesh 2.6 | 1781604724 ≤ 𝑥 < * | ADP |
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache2 |
| ||||||||||||||||
| nginx |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache2 |
| ||||||||||||||||||||
| apache2-devel |
| ||||||||||||||||||||
| apache2-doc |
| ||||||||||||||||||||
| apache2-example-pages |
| ||||||||||||||||||||
| apache2-manual |
| ||||||||||||||||||||
| apache2-prefork |
| ||||||||||||||||||||
| apache2-tls13 |
| ||||||||||||||||||||
| apache2-tls13-devel |
| ||||||||||||||||||||
| apache2-tls13-doc |
| ||||||||||||||||||||
| apache2-tls13-example-pages |
| ||||||||||||||||||||
| apache2-tls13-prefork |
| ||||||||||||||||||||
| apache2-tls13-utils |
| ||||||||||||||||||||
| apache2-tls13-worker |
| ||||||||||||||||||||
| apache2-utils |
| ||||||||||||||||||||
| apache2-worker |
|
Amazon Linux Releases
Azure Linux Releases
Common Weakness Enumeration
- CWE-789 - Memory Allocation with Excessive Size ValueThe product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
- CWE-409 - Improper Handling of Highly Compressed Data (Data Amplification)The software does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.
Vulnerability Media Exposure
References