Sceawere
Vulnerability Detail
CVE-2026-59685UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Apache HTTP Server OOB Write
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 1d ago
- Vendor
- Apache Software Foundation
- Product
- Apache HTTP Server
- Attack Type
- CWE-787 Out-of-bounds Write
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-01T17:17:29.380Z",
"pubdate": "2026-10-01T17:17:29.380Z",
"executiveSummary": "A critical out-of-bounds write vulnerability has been identified in Apache HTTP Server versions 2.4.0 through 2.4.68 when deployed on Windows operating systems.\nThe vulnerability stems from improper handling of 8.3 short filename expansions during path processing. When a path containing 8.3 filenames is expanded, the resulting string can exceed the buffer allocated for the operation, leading to a memory corruption scenario.\nThis flaw presents a significant risk as it allows for arbitrary memory modification, which may lead to remote code execution or a denial-of-service state depending on the surrounding memory layout and exploitation success.\nThe vulnerability is restricted to the Windows platform due to the specific handling of 8.3 path conventions. Successful exploitation requires an attacker to provide a specially crafted request that triggers the insecure path expansion mechanism within the server's request handling logic.\nNo authentication is required to trigger the vulnerability, as it exists within the core path-processing routines accessible to unauthenticated remote users.",
"technicalDetails": "The root cause of this vulnerability lies in the improper size calculation during the expansion of 8.3 (short) filenames on Windows-based Apache HTTP Server instances. In the Windows file system, files and directories can be referenced using 8.3 aliases, which are frequently expanded to their full-length equivalents for internal processing and verification.\nDuring the path normalization and resolution process, the server allocates a destination buffer for the expanded path string. The vulnerability occurs when the logic fails to account for the potential expansion factor between the original 8.3 format and the full long-filename equivalent. If the expanded path length exceeds the pre-allocated buffer size, an out-of-bounds write occurs.\nThe attack flow initiates when a remote, unauthenticated attacker transmits a crafted HTTP request containing a path string formatted to utilize 8.3 naming conventions. The server intercepts this request and passes the path to the internal routines responsible for Windows file system path resolution. As the server attempts to expand the 8.3 components into their full path representation, the internal function writes the resulting characters past the boundary of the allocated heap or stack buffer.\nBecause this operation involves writing data into memory regions adjacent to the buffer, an attacker can potentially overwrite critical control structures, such as function pointers, return addresses, or object metadata, depending on the memory architecture and compiler-specific memory layout. By carefully crafting the input string, an attacker can influence the overwritten data, potentially redirecting the execution flow to attacker-controlled code or payloads.\nThe vulnerability affects Apache HTTP Server versions 2.4.0 through 2.4.68. The impact is primarily localized to the Windows platform, as the specific mechanism of 8.3 path expansion is a legacy feature of the Windows file system (NTFS/FAT). The exploitability of the buffer overflow is contingent upon the memory allocator's behavior and the presence of stack or heap protections (such as ASLR or DEP), which may mitigate the effectiveness of a direct code execution attack but cannot prevent the underlying out-of-bounds write from causing a service crash, leading to a denial-of-service condition."
}