CVE-2026-49975: Apache HTTP Server

High severity, CVSS 7.5. EPSS: 4.2% chance of exploitation in the next 30 days.

Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.

Affected products

  • Apache HTTP Server: from 2.4.17, before 2.4.68 (fixed in 2.4.68)
  • Debian Debian Linux: version 11.0 only

Published 2026-06-08. Last modified 2026-08-19.