CVE-2021-26691

Updated: 2025-08-20 02:29:45.198275

Description:

In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x HIGH 7.5
CVSS Version 3.x CRITICAL 9.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

CentOS 7 ELS httpd 2.4.6 9.8 CRITICAL Already Fixed 2023-09-19 09:30:23
CentOS 8.4 ELS httpd 2.4.37 9.8 CRITICAL Already Fixed 2023-10-26 17:22:13
CentOS 8.5 ELS httpd 2.4.37 9.8 CRITICAL Already Fixed 2023-10-26 17:21:47
Oracle Linux 7 ELS httpd 2.4.6 9.8 CRITICAL In Testing 2026-01-13 20:38:34
Ubuntu 16.04 ELS apache2 2.4.18 9.8 CRITICAL Released CLSA-2021:1635459129 2022-03-25 15:44:41
Ubuntu 18.04 ELS apache2 2.4.29 9.8 CRITICAL Already Fixed 2023-04-28 08:48:57