{"id":"AZL-106485","summary":"CVE-2026-63292 affecting package httpd 2.4.68-1","details":"Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue.","modified":"2026-10-08T05:35:32Z","published":"2026-10-01T17:17:29Z","upstream":["CVE-2026-63292"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63292"}],"affected":[{"package":{"name":"httpd","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/httpd"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.4.68-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106485.json"}}],"schema_version":"1.9.0"}