7.5
CVSSv2

CVE-2021-26691

Published: 10/06/2021 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache http server

debian debian linux 9.0

debian debian linux 10.0

fedoraproject fedora 34

fedoraproject fedora 35

oracle instantis enterprisetrack 17.1

oracle instantis enterprisetrack 17.2

oracle instantis enterprisetrack 17.3

oracle enterprise manager ops center 12.4.0.0

oracle zfs storage appliance kit 8.8

oracle secure backup

netapp cloud backup -

Vendor Advisories

Several vulnerabilities have been found in the Apache HTTP server, which could result in denial of service In addition the implementation of the MergeSlashes option could result in unexpected behaviour For the stable distribution (buster), these problems have been fixed in version 2438-3+deb10u5 We recommend that you upgrade your apache2 packa ...
A flaw was found in Apache httpd The mod_proxy_wstunnel module tunnels non-upgraded connections (CVE-2019-17567) A flaw was found in HTTPd In some Apache HTTP Server versions, unprivileged local users can stop HTTPd on Windows The highest threat from this vulnerability is to system availability (CVE-2020-13938) A flaw was found In Apache httpd ...
A flaw was found in Apache httpd The mod_proxy_wstunnel module tunnels non-upgraded connections (CVE-2019-17567) A flaw was found in HTTPd In some Apache HTTP Server versions, unprivileged local users can stop HTTPd on Windows The highest threat from this vulnerability is to system availability (CVE-2020-13938) A flaw was found In Apache httpd ...
A heap overflow flaw was found In Apache httpd mod_session The highest threat from this vulnerability is to system availability ...
In Apache HTTP Server versions 240 to 2446, a specially crafted SessionHeader sent by an origin server could cause a heap overflow ...

ICS Advisories

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2021-26691: Apache httpd: mod_session response handling heap overflow <!--X-Subject-Header-End--> <!--X-Head-of-Message--> ...

Github Repositories

blackbox-scan This tool is a command-line client for the BlackBox API, that can help to integrate Dynamic Application Security Testing (DAST) into a CI/CD pipeline Requirements Python version 362 or above is required to run the tool The use of virtualenv is recommended To install required Python packages, run: pip install -r requirementstxt