CVE-2026-44631: Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow
Published Jun 8, 2026
·Updated
Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration.
Affected Software
4 affected componentsFixes available
Apache HTTP Server>=2.4.0<=2.4.67
Apache HTTP Server>=2.4.0<2.4.68
Microsoft azl3 httpd 2.4.67-1
debian/apache2<=2.4.62-1~deb11u1, <=2.4.67-1~deb12u3, <=2.4.67-1~deb13u3
2.4.67-1~deb11u32.4.68-1~deb12u12.4.68-1~deb13u12.4.68-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.67-1~deb11u3Fixed in 2.4.68-1~deb12u1Fixed in 2.4.68-1~deb13u1Fixed in 2.4.68-1 - Upgrade
Upgrade
Apache HTTP Serverto a version that resolves this vulnerability.Fixed in 2.4.68Patch CVE-2026-44631
Event History
Jun 8, 2026
CVE Published
via MITRE·03:19 PM
Data Sourced
via MITRE·03:19 PM
DescriptionWeakness
Data Sourced
via Red Hat·04:02 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Jun 11, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeaknessAffected Software
Jul 8, 2026
Data Sourced
via Launchpad·03:47 PM
Description
Jul 20, 2026
Data Sourced
via Debian·10:12 PM
DescriptionAffected Software
Jul 21, 2026
Data Sourced
via Ubuntu·10:11 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-44631?
CVE-2026-44631 has a risk rating of 50, indicating moderate severity.
2
How do I fix CVE-2026-44631?
To fix CVE-2026-44631, you should upgrade to Apache HTTP Server version 2.4.68.
3
What is the impact of CVE-2026-44631?
CVE-2026-44631 can lead to a buffer underwrite vulnerability affecting Apache HTTP Server's handling of crafted regular expressions.
4
Which versions of Apache HTTP Server are affected by CVE-2026-44631?
CVE-2026-44631 affects Apache HTTP Server versions from 2.4.0 to 2.4.67.
5
When was CVE-2026-44631 published?
CVE-2026-44631 was published on June 8, 2026.