CVE-2026-49975

HIGH CVSS 3.1: 7.5 EPSS 28.0%
Updated Jul 23, 2026
Debian
Parameter Value
CVSS 7.5 (HIGH)
Affected Versions 2.4.17 — 2.4.68
Fixed In 2.4.68
Type CWE-789, CWE-409
Vendor Debian
Public PoC No

Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 2

Configuration From (including) Up to (excluding)
Apache Http_Server
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
2.4.17 2.4.68
Debian Debian_Linux
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

References 18

https://httpd.apache.org/security/vulnerabilities_24.html
security@apache.org
http://www.openwall.com/lists/oss-security/2026/06/03/3
af854a3a-2127-422b-91ae-364da2661108
http://www.openwall.com/lists/oss-security/2026/06/08/16
af854a3a-2127-422b-91ae-364da2661108
https://lists.debian.org/debian-lts-announce/2026/06/msg00009.html
af854a3a-2127-422b-91ae-364da2661108
https://access.redhat.com/errata/RHSA-2026:25042
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:25057
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:25090
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:25225
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:27114
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:27200
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:27201
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:36373
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:36831
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:36846
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/security/cve/CVE-2026-49975
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://bugzilla.redhat.com/show_bug.cgi?id=2485371
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://github.com/EQSTLab/CVE-2026-49975
134c704f-9b21-4f2e-91b3-4a467353bcc0
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49975.json
0b0ca135-0b70-47e7-9f44-1890c2a1c46c