CVE-2021-26691

CRITICAL9.8EPSS 47.8%

Apache HTTP Server mod_session response handling heap overflow

Published: 6/10/2021Modified: 4/28/2026

Description

In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (16)