Medium severity6.5NVD Advisory· Published Jun 8, 2026· Updated Jun 11, 2026
CVE-2026-43951
CVE-2026-43951
Description
Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*range: >=2.4.0,<=2.4.67
- (no CPE)range: 2.4.0 through 2.4.67
- osv-coords2 versions
>= 2.4.0, < 2.4.68+ 1 more
- (no CPE)range: >= 2.4.0, < 2.4.68
- (no CPE)range: < 2.0.29-4.el10_2.2
Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/06/08/10nvdMailing ListThird Party Advisory
- httpd.apache.org/security/vulnerabilities_24.htmlnvdVendor Advisory
News mentions
2- Apache HTTP Server and Answer: 22 Vulnerabilities Disclosed, Including Critical FlawsVypr Intelligence · Jun 10, 2026
- Apache HTTP Server 2.4.68 Released With Fix For Use-After-Free, DoS, XSS, and Buffer Overflow FlawsCyber Security News · Jun 9, 2026