CVE-2021-26691: Apache HTTP Server mod_session response handling heap overflow
A heap overflow flaw was found In Apache httpd modsession. The highest threat from this vulnerability is to system availability.
Other sources
In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow
In Apache httpd before 2.4.48 modsession has a heap overflow.
References:
https://github.com/apache/httpd/commit/7e09dd714fc62c08c5b0319ed7b9702594faf49b
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-26691?
CVE-2021-26691 is a heap overflow vulnerability in Apache httpd mod_session.
How does CVE-2021-26691 affect Apache HTTP Server?
CVE-2021-26691 affects Apache HTTP Server versions 2.4.0 to 2.4.46 and can cause a heap overflow when a specially crafted SessionHeader is sent by an origin server.
What is the severity of CVE-2021-26691?
CVE-2021-26691 has a severity rating of 9.8 (Critical).
How can I fix CVE-2021-26691?
To fix CVE-2021-26691, update your Apache HTTP Server to version 2.4.47 or higher.
Where can I find more information about CVE-2021-26691?
You can find more information about CVE-2021-26691 at the following references: [GitHub](https://github.com/apache/httpd/commit/7e09dd714fc62c08c5b0319ed7b9702594faf49b), [Red Hat Security Policy](https://access.redhat.com/support/policy/updates/jboss_notes), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1969233).