Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests.
This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade httpd-develUpgrade mod_mdUpgrade httpdUpgrade httpd-toolsUpgrade mod_ldapUpgrade httpd-filesystemUpgrade mod_sslUpgrade mod_sessionUpgrade mod_proxy_htmlUpgrade httpd-manualUpgrade mod_http2 | Jun 16, 2026 | Jun 10, 2026 |
| Alpine Linux | — | Upgrade apache2Upgrade nginx | Jun 9, 2026 | Jun 8, 2026 |
| Amazon Linux Ami 2 | — | Upgrade mod_http2-debuginfoUpgrade mod_http2 | Jun 23, 2026 | Jun 23, 2026 |
| Amazon_linux_2023 | — | Upgrade mod_http2-debugsourceUpgrade mod_http2Upgrade mod_http2-debuginfo | Jun 23, 2026 | Jun 8, 2026 |
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Jun 9, 2026 | Jun 8, 2026 |
| Debian | — | Upgrade apache2 | Jun 7, 2026 | Jun 7, 2026 |
| Freebsd | — | Upgrade apache24 | Jun 15, 2026 | Jun 4, 2026 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Aug 16, 2026 | Aug 13, 2026 |
| Redhat_linux | — | Upgrade httpd-manualUpgrade httpd-debugsourceUpgrade httpd-tools-debuginfoUpgrade httpd-debuginfoUpgrade mod_session-debuginfoUpgrade mod_http2Upgrade mod_ldapUpgrade mod_proxy_htmlUpgrade mod_md-debuginfoUpgrade mod_http2-debugsourceUpgrade mod_proxy_html-debuginfoUpgrade mod_sslUpgrade mod_sessionUpgrade httpd-filesystemUpgrade mod_ssl-debuginfoUpgrade mod_md-debugsourceUpgrade httpdUpgrade mod_mdUpgrade httpd-toolsUpgrade httpd-develUpgrade mod_ldap-debuginfoUpgrade mod_http2-debuginfo | Jun 12, 2026 | Jun 3, 2026 |
| Rocky_linux | — | Upgrade mod_sslUpgrade mod_http2-debuginfoUpgrade httpd-tools-debuginfoUpgrade httpd-debuginfoUpgrade httpd-develUpgrade mod_md-debuginfoUpgrade mod_md-debugsourceUpgrade mod_mdUpgrade httpdUpgrade mod_sessionUpgrade httpd-debugsourceUpgrade mod_proxy_htmlUpgrade mod_http2Upgrade mod_ssl-debuginfoUpgrade mod_ldap-debuginfoUpgrade mod_session-debuginfoUpgrade mod_http2-debugsourceUpgrade mod_ldapUpgrade httpd-toolsUpgrade mod_proxy_html-debuginfo | Jun 17, 2026 | Jun 13, 2026 |
| Ubuntu | — | Upgrade apache2-mpm-worker (Ubuntu Pro)Upgrade apache2-utils (Ubuntu Pro)Upgrade nginx-lightUpgrade apache2-mpm-itk (Ubuntu Pro)Upgrade nginxUpgrade nginx-fullUpgrade nginx-full (Ubuntu Pro)Upgrade apache2-dev (Ubuntu Pro)Upgrade libapache2-mod-proxy-uwsgi (Ubuntu Pro)Upgrade nginx-extrasUpgrade apache2-bin (Ubuntu Pro)Upgrade apache2-suexec-custom (Ubuntu Pro)Upgrade apache2-suexec (Ubuntu Pro)Upgrade apache2.2-bin (Ubuntu Pro)Upgrade apache2-mpm-event (Ubuntu Pro)Upgrade libapache2-mod-macro (Ubuntu Pro)Upgrade nginx-core (Ubuntu Pro)Upgrade apache2-suexec-pristine (Ubuntu Pro)Upgrade apache2 (Ubuntu Pro)Upgrade libapache2-mod-proxy-html (Ubuntu Pro)Upgrade nginx-light (Ubuntu Pro)Upgrade nginx-coreUpgrade apache2-mpm-prefork (Ubuntu Pro)Upgrade nginx-extras (Ubuntu Pro)Upgrade libapache2-mod-md (Ubuntu Pro)Upgrade apache2-ssl-dev (Ubuntu Pro)Upgrade nginx (Ubuntu Pro)Upgrade nginx-common (Ubuntu Pro)Upgrade apache2 | Jun 7, 2026 | Jun 4, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 17, 2026 | Jun 8, 2026 |
| Zimbra Collaboration | — | Upgrade Zimbra Collaboration to the latest version | Jun 18, 2026 | Jun 8, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub