https://seclists.org/oss-sec/2026/q2/843: CVE-2026-44631: Apache HTTP Server: Heap Underflow in `ap_gname` via Signed Char Overflow
Published Jun 8, 2026
·Updated
Affected Software
1 affected component
Apache HTTP Server>=2.4.0<=2.4.67
Frequently Asked Questions
1
What is the severity of CVE-2026-44631?
The severity of CVE-2026-44631 is classified as low.
2
Which versions of Apache HTTP Server are affected by CVE-2026-44631?
CVE-2026-44631 affects Apache HTTP Server versions from 2.4.0 through 2.4.67.
3
How do I fix CVE-2026-44631?
To fix CVE-2026-44631, upgrade Apache HTTP Server to a version higher than 2.4.67.
4
What type of vulnerability is CVE-2026-44631?
CVE-2026-44631 is a buffer underwrite vulnerability caused by crafted regular expressions in the Apache HTTP Server configuration.
5
When was CVE-2026-44631 published?
CVE-2026-44631 was published on June 8, 2026.