Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-43951

Опубликовано: 08 июн. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.

A flaw was found in Apache HTTP Server. An out-of-bounds read vulnerability exists when mod_headers and mod_mime are used with multiple response languages. This could allow a remote attacker to disclose sensitive information from memory or cause a denial of service.

Отчет

This Moderate impact vulnerability in Apache HTTP Server arises from an out-of-bounds read when both mod_headers and mod_mime modules are active and configured for multiple response languages. While this configuration is not universally enabled by default in Red Hat products, affected systems could be vulnerable to information disclosure or denial of service if these specific modules and language settings are in use. Exploitation requires a remote attacker to trigger this specific module interaction.

Меры по смягчению последствий

  • Those who do not require multi-language response headers can remove or disable the mod_headers and mod_mime modules, or remove Content-Language directives from their configuration.
  • Systems not using these modules in combination are not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6httpdOut of support scope
Red Hat Enterprise Linux 7httpdOut of support scope
Red Hat Enterprise Linux 8httpdAffected
Red Hat Enterprise Linux 8mod_http2Affected
Red Hat Enterprise Linux 9httpdAffected
Red Hat Enterprise Linux 9mod_http2Affected
Red Hat Hardened ImageshttpdAffected
Red Hat JBoss Core Servicesjbcs-httpd24-mod_http2Fix deferred
Red Hat JBoss Core Servicesmod_http2.soFix deferred
Red Hat Enterprise Linux 10httpdFixedRHSA-2026:3410901.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2486415httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime

EPSS

Процентиль: 42%
0.00545
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 месяцев назад

Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.

CVSS3: 6.5
nvd
около 2 месяцев назад

Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.

msrc
около 2 месяцев назад

Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash

CVSS3: 6.5
debian
около 2 месяцев назад

Out-of-bounds Read vulnerability in Apache HTTP Server with mod_header ...

CVSS3: 6.5
github
около 2 месяцев назад

Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.

EPSS

Процентиль: 42%
0.00545
Низкий

6.5 Medium

CVSS3