← All CVEs

CVE-2021-26691

critical · 9.8

In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow

9.8
CVSS
68.3%
EPSS (exploit prob.)
99th
EPSS percentile
2021-06-10
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-122CWE-787

Affected products

VendorProductAffected versions
apachehttp_server>= 2.4.0, <= 2.4.46
debiandebian_linux9.0
debiandebian_linux10.0
fedoraprojectfedora34
fedoraprojectfedora35
oracleenterprise_manager_ops_center12.4.0.0
oracleinstantis_enterprisetrack17.1
oracleinstantis_enterprisetrack17.2
oracleinstantis_enterprisetrack17.3
oraclesecure_backup< 18.1.0.1.0
oraclezfs_storage_appliance_kit8.8
netappcloud_backupall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-26691