CVE-2026-42536
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
- Affected products
- Apache Http Server, Linuxmint, Red Os, Rocky Linux, Ubuntu
- Apache Http Server
- < 2.4.68
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 1.0% (62th percentile)
- Weakness
- CWE-120, CWE-122
- NVD status
- Modified
- Published
- 2026-06-08
CVE-2026-42536 at NVD
1 known exploit for CVE-2026-42536
Proof-of-concept code and exploit modules indexed by Sploitus