Description
Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages.

This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Published: 2026-06-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an out‑of‑bounds read in the Apache HTTP Server's merge_response_headers routine, which is invoked when mod_headers, mod_mime, and multiple response languages are enabled. The out‑of‑bounds read can trigger a memory access violation that crashes the server, causing a denial of service. The weakness is classified as CWE‑125. The CVE does not state that the crash leads to arbitrary code execution, only that the server terminates unexpectedly.

Affected Systems

The affected product is Apache HTTP Server from the Apache Software Foundation. Vulnerable releases range from 2.4.0 to 2.4.67 inclusive. Any installation that has the mod_headers and mod_mime modules loaded and is configured to use multiple response languages is exposed to this flaw.

Risk and Exploitability

The CVSS score is 6.5, indicating moderate severity. No exploit probability score is published and the vulnerability is not listed in the CISA KEV catalog. The attack vector is most likely network‑based, since the out‑of‑bounds read occurs while the server processes incoming HTTP requests and does not require authentication. Because the flaw results in an OOB read that can crash the server, an attacker may use the vulnerability to cause repeated service outages, a denial of service. The conditions for exploitation require that the affected modules, mod_headers and mod_mime, be loaded and that multiple response languages be enabled, which limits the probability of exploitation but does not eliminate it. The impact of a successful attack could lead to forced restarts or downtime for the target web server.

Generated by OpenCVE AI on June 8, 2026 at 21:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache HTTP Server to version 2.4.68 or later.
  • If upgrading is not immediately possible, disable the mod_headers or mod_mime modules or remove multiple response language support to mitigate the effect of the OOB read.
  • Apply any vendor security advisories that contain configuration changes or patches addressing the merge_response_headers flaw.

Generated by OpenCVE AI on June 8, 2026 at 21:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 08 Jun 2026 23:30:00 +0000

Type Values Removed Values Added
References

Mon, 08 Jun 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 08 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache http Server
Vendors & Products Apache
Apache http Server

Mon, 08 Jun 2026 15:45:00 +0000

Type Values Removed Values Added
Description Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Title Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash
Weaknesses CWE-125
References

Subscriptions

Apache Http Server
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-06-08T22:32:28.584Z

Reserved: 2026-05-04T17:15:44.253Z

Link: CVE-2026-43951

cve-icon Vulnrichment

Updated: 2026-06-08T22:32:28.584Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-08T16:16:40.087

Modified: 2026-06-09T01:41:00.563

Link: CVE-2026-43951

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-08T21:15:33Z

Weaknesses