CVE-2026-63292 is a stack-based buffer overflow in Apache HTTP Server's mod_vhost_alias module affecting versions 2.4.0 through 2.4.68 on all platforms. When VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above its default, a remote unauthenticated client can trigger the overflow with an HTTP Host header exceeding 8,192 bytes. Exploitation can cause denial of service and potentially arbitrary code execution. Apache HTTP Server 2.4.69 fixes the vulnerability.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stack-based buffer overflow in Apache HTTP Server mod_vhost_alias that can crash workers and may permit remote code execution under a specific non-default configuration.
Listed as an Apache HTTP Server vulnerability covered by the Nessus plugin. Flaw-specific technical details are not provided.
A remotely triggerable stack-based buffer overflow affects Apache HTTP Server's mod_vhost_alias through version 2.4.68 on all platforms. Exploitation requires a Host header longer than 8192 bytes, a hostname format specifier in VirtualDocumentRoot, and LimitRequestFieldSize raised above its default. The potential impact is denial of service or arbitrary code execution. Version 2.4.69 fixes the issue.
A vulnerability in the FreeBSD Apache httpd (apache24) package referenced by the FreeBSD security advisory; no technical flaw details are provided.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.