Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42536

Опубликовано: 08 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

A flaw was found in Apache HTTP Server, specifically within the mod_xml2enc module. This heap-based buffer overflow vulnerability can be triggered when processing untrusted content through the xml2StartParse function. A remote attacker could potentially exploit this to cause a denial of service, information disclosure, or possibly arbitrary code execution.

Отчет

In Red Hat Enterprise Linux (RHEL), the httpd package includes mod_xml2enc, which provides encoding support for filters like mod_proxy_html. Because this flaw relies on processing unvetted or untrusted input text lengths, the impact presents a high risk to availability (Denial of Service via worker crashes) and a potential risk to confidentiality if an attacker is capable of executing remote code within the context of the apache or httpd daemon process.

Меры по смягчению последствий

To mitigate this vulnerability, disable the mod_xml2enc module if its functionality for XML internationalization is not essential. This can be done by commenting out the LoadModule xml2enc_module modules/mod_xml2enc.so directive in the Apache HTTP Server configuration. A service restart is required for the change to take effect.

# Edit the Apache configuration file, e.g., /etc/httpd/conf.modules.d/00-base.conf # Comment out the line: # LoadModule xml2enc_module modules/mod_xml2enc.so # Reload the httpd service sudo systemctl reload httpd

Note: Disabling mod_xml2enc will cause any configurations relying heavily on mod_proxy_html or raw HTML/XML encoding conversions to function incorrectly or fail. Red Hat strongly recommends upgrading to a patched version of httpd as soon as it becomes available for your specific RHEL channel.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6httpdAffected
Red Hat Enterprise Linux 7httpdAffected
Red Hat Enterprise Linux 10httpdFixedRHSA-2026:3410901.07.2026
Red Hat Enterprise Linux 8httpdFixedRHSA-2026:4282821.07.2026
Red Hat Enterprise Linux 9httpdFixedRHSA-2026:4190620.07.2026
Red Hat Hardened Imageshttpd-main-2.4.68-1.hum1FixedRHSA-2026:2504210.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2486411httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc

EPSS

Процентиль: 58%
0.0096
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

CVSS3: 7.5
nvd
около 2 месяцев назад

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

msrc
около 2 месяцев назад

Apache HTTP Server: mod_xml2enc heap overflow

CVSS3: 7.5
debian
около 2 месяцев назад

Heap-based Buffer Overflow vulnerability in Apache HTTP Server withmod ...

CVSS3: 7.5
github
около 2 месяцев назад

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

EPSS

Процентиль: 58%
0.0096
Низкий

7.5 High

CVSS3