Fedora Account System
Red Hat Associate
Red Hat Customer
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:34109 https://access.redhat.com/errata/RHSA-2026:34109
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:41906 https://access.redhat.com/errata/RHSA-2026:41906
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:42828 https://access.redhat.com/errata/RHSA-2026:42828
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:47046 https://access.redhat.com/errata/RHSA-2026:47046
This issue has been addressed in the following products: Red Hat JBoss Core Services 2.4.62.SP5 Via RHSA-2026:56869 https://access.redhat.com/errata/RHSA-2026:56869
This issue has been addressed in the following products: JBoss Core Services for RHEL 8 Via RHSA-2026:56868 https://access.redhat.com/errata/RHSA-2026:56868
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:62165 https://access.redhat.com/errata/RHSA-2026:62165
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:66323 https://access.redhat.com/errata/RHSA-2026:66323
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:67152 https://access.redhat.com/errata/RHSA-2026:67152
CVE-2026-42536: Public exploit available An exploit for CVE-2026-42536, a heap-based buffer overflow in Apache HTTP Server's mod_xml2enc module, has been published. Exploit: https://github.com/erberkan/CVE-2026-42536-PoC Red Hat CVE: https://access.redhat.com/security/cve/cve-2026-42536 Please review the exploit and confirm the impact on supported RHEL versions and the remediation status.