Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4187 articles · 181334 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-44631PATCHED
apache · http_server

Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow

Description

Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

Affected Products

VendorProductVersions
apachehttp_server2.4.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apachehttpcert_advisory90%
oraclesolariscert_advisory90%

References

  • https://httpd.apache.org/security/vulnerabilities_24.html(vendor-advisory)

Related News (5 articles)

Tier B
BSI Advisories6d ago
[NEU] [hoch] Oracle Solaris Drittanbieterkomponenten: Mehrere Schwachstellen
→ No new info (linked only)
Tier A
Microsoft MSRC47d ago
CVE-2026-44631 Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow
→ No new info (linked only)
Tier B
BSI Advisories49d ago
[NEU] [hoch] Apache HTTP Server: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
oss-security49d ago
CVE-2026-44631: Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow
→ No new info (linked only)
Tier C
VulDB50d ago
CVE-2026-44631 | Apache HTTP Server up to 2.4.67 ap_regname heap-based overflow
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://httpd.apache.org/security/vulnerabilities_24.html
CWECWE-124
PublishedJun 8, 2026
Last enriched49d ago
Trending Score33
Source articles5
Independent4
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-23918EXP
Apache HTTP Server: http2: double free and possible RCE on early reset
Trending: 91
CRITICALCVE-2026-41293EXP
Apache Tomcat: HTTP/2 request headers not validated
Trending: 36
NONECVE-2026-49975EXP
Apache HTTP Server: mod_http2 denial of service
Trending: 36
CRITICALCVE-2026-43512
Apache Tomcat: Digest authenticator will authenticate any unknown user
Trending: 35
HIGHCVE-2026-29167EXP
Apache HTTP Server: mod_ldap per-dir use-after-free
Trending: 34

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 8, 2026
Discovered by ZDM
Jun 8, 2026
Patch Available
Jun 8, 2026