CVE-2026-43951: Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash
Last updated 20 July 2026
Other sources
Out-of-bounds Read vulnerability in Apache HTTP Server with modheaders and modmime and multiple response languages.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.67-1~deb11u3Fixed in 2.4.68-1~deb12u1Fixed in 2.4.68-1~deb13u1Fixed in 2.4.68-1 - Upgrade
Upgrade
Apache HTTP Serverto a version that resolves this vulnerability.Fixed in 2.4.68Patch CVE-2026-43951
Event History
Frequently Asked Questions
What is the severity of CVE-2026-43951?
CVE-2026-43951 has a risk rating of 25, indicating a moderate severity level.
How do I fix CVE-2026-43951?
To fix CVE-2026-43951, update your Apache HTTP Server to version 2.4.68 or later.
What versions of Apache HTTP Server are affected by CVE-2026-43951?
CVE-2026-43951 affects Apache HTTP Server versions from 2.4.0 through 2.4.67.
What is the impact of CVE-2026-43951?
CVE-2026-43951 can cause an out-of-bounds read condition that may lead to a crash of the Apache HTTP Server.
Is there a workaround for CVE-2026-43951?
There are no specific workarounds for CVE-2026-43951; upgrading to the latest version is recommended for mitigation.