CVE-2026-42536: Apache HTTP Server: mod_xml2enc heap overflow
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with modxml2enc, xml2StartParse, and untrusted content
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.67-1~deb11u3Fixed in 2.4.68-1~deb12u1Fixed in 2.4.68-1~deb13u1Fixed in 2.4.68-1 - Upgrade
Upgrade
Apache HTTP Server (mod_xml2enc)to a version that resolves this vulnerability.Fixed in 2.4.68Patch CVE-2026-42536
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42536?
CVE-2026-42536 has a risk rating of 60, indicating a medium level of severity.
How do I fix CVE-2026-42536?
To fix CVE-2026-42536, users should upgrade Apache HTTP Server to version 2.4.68 or later.
What is the cause of CVE-2026-42536?
CVE-2026-42536 is caused by a heap-based buffer overflow vulnerability in the mod_xml2enc module of Apache HTTP Server.
Which versions of Apache HTTP Server are affected by CVE-2026-42536?
Apache HTTP Server versions from 2.4.0 through 2.4.67 are affected by CVE-2026-42536.
What component of Apache HTTP Server is vulnerable in CVE-2026-42536?
CVE-2026-42536 affects the mod_xml2enc component of the Apache HTTP Server.