Bug 2486411 (CVE-2026-42536) - CVE-2026-42536 httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc
Summary: CVE-2026-42536 httpd: Apache HTTP Server: Heap-based Buffer Overflow via untr...
Keywords:
Status: NEW
Alias: CVE-2026-42536
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2490330
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-08 16:02 UTC by OSIDB Bzimport
Modified: 2026-09-15 01:56 UTC (History)
10 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:34109 0 None None None 2026-07-01 09:14:47 UTC
Red Hat Product Errata RHSA-2026:41906 0 None None None 2026-07-20 06:28:33 UTC
Red Hat Product Errata RHSA-2026:42828 0 None None None 2026-07-21 15:41:03 UTC
Red Hat Product Errata RHSA-2026:47046 0 None None None 2026-07-28 08:59:47 UTC
Red Hat Product Errata RHSA-2026:56868 0 None None None 2026-08-19 13:32:48 UTC
Red Hat Product Errata RHSA-2026:56869 0 None None None 2026-08-19 13:28:51 UTC
Red Hat Product Errata RHSA-2026:62165 0 None None None 2026-09-01 17:41:33 UTC
Red Hat Product Errata RHSA-2026:66323 0 None None None 2026-09-10 05:41:06 UTC
Red Hat Product Errata RHSA-2026:67152 0 None None None 2026-09-14 13:36:26 UTC

Description OSIDB Bzimport 2026-06-08 16:02:41 UTC
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content

This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.

Users are recommended to upgrade to version 2.4.68, which fixes the issue.

Comment 2 errata-xmlrpc 2026-07-01 09:14:45 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:34109 https://access.redhat.com/errata/RHSA-2026:34109

Comment 3 errata-xmlrpc 2026-07-20 06:28:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:41906 https://access.redhat.com/errata/RHSA-2026:41906

Comment 4 errata-xmlrpc 2026-07-21 15:41:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:42828 https://access.redhat.com/errata/RHSA-2026:42828

Comment 5 errata-xmlrpc 2026-07-28 08:59:46 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:47046 https://access.redhat.com/errata/RHSA-2026:47046

Comment 7 errata-xmlrpc 2026-08-19 13:28:50 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Core Services 2.4.62.SP5

Via RHSA-2026:56869 https://access.redhat.com/errata/RHSA-2026:56869

Comment 8 errata-xmlrpc 2026-08-19 13:32:47 UTC
This issue has been addressed in the following products:

  JBoss Core Services for RHEL 8

Via RHSA-2026:56868 https://access.redhat.com/errata/RHSA-2026:56868

Comment 9 errata-xmlrpc 2026-09-01 17:41:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:62165 https://access.redhat.com/errata/RHSA-2026:62165

Comment 10 errata-xmlrpc 2026-09-10 05:41:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:66323 https://access.redhat.com/errata/RHSA-2026:66323

Comment 11 Jon Orris 2026-09-14 13:36:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:67152 https://access.redhat.com/errata/RHSA-2026:67152

Comment 12 Akiyoshi Kurita 2026-09-15 01:56:07 UTC
CVE-2026-42536: Public exploit available

An exploit for CVE-2026-42536, a heap-based buffer overflow in Apache HTTP Server's mod_xml2enc module, has been published.

Exploit:
https://github.com/erberkan/CVE-2026-42536-PoC

Red Hat CVE:
https://access.redhat.com/security/cve/cve-2026-42536

Please review the exploit and confirm the impact on supported RHEL versions and the remediation status.


Note You need to log in before you can comment on or make changes to this bug.