Out-of-Bounds Write Vulnerability in Apache HTTP Server on Windows
CVE-2026-59685

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
1 October 2026

What is CVE-2026-59685?

An out-of-bounds write vulnerability exists in the Apache HTTP Server running on Windows. This vulnerability arises when the server processes paths with 8.3 filenames that may expand beyond their allocated buffer, potentially allowing an attacker to manipulate memory. Recovering from this can lead to unexpected behavior or crashes in the server, thereby compromising its integrity and reliability. Administering proper validation and sanitization of paths is essential to mitigate potential exploits associated with this vulnerability.

Affected Version(s)

Apache HTTP Server 2.4.0 <= 2.4.68

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dhiraj Mishra
Feng Ning (innora.ai / Innora Security Research)
.