Vulnerability record · CVE-2021-26691 · published 10 June 2021
CVE-2021-26691: Apache HTTP Server heap overflow via crafted SessionHeader
Apache · Http Server
Apache HTTP Server versions 2.4.0 through 2.4.46 contain a heap-based buffer overflow triggered when a specially crafted SessionHeader is sent by an origin server. The flaw is an out-of-bounds write in the mod_session handling path, and it matters because it can corrupt heap memory in a widely deployed server component.
Description
In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCritical CVSS 9.8 with very high EPSS, but exploitation requires a malicious origin server and the flaw is not in KEV, so it ranks below actively exploited issues.
What it is
Apache HTTP Server versions 2.4.0 through 2.4.46 contain a heap-based buffer overflow triggered when a specially crafted SessionHeader is sent by an origin server. The flaw is an out-of-bounds write in the mod_session handling path, and it matters because it can corrupt heap memory in a widely deployed server component.
Impact
An attacker can write out of bounds on the heap, which can crash the server and, depending on heap layout, may lead to remote code execution in the context of the httpd process. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
The vector is network reachable with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N). The description states the malicious SessionHeader comes from an origin server, so the trigger is a server-to-server or proxy path rather than a direct client request, and the record does not detail the exact deployment configuration required.
Exploitation
CVE-2021-26691 is not listed in CISA KEV and no ransomware groups are documented using it, but EPSS is high at roughly 0.68 probability over 30 days (99.3rd percentile), indicating elevated predicted exploitation activity. References are vendor advisories, mailing lists and patch notices; none are tagged as exploit code.
What to do
- Upgrade Apache HTTP Server to a version after 2.4.46 that contains the fix, per the Apache security advisory.
- Apply distribution backports for Debian, Fedora, Gentoo and other packaged builds, and vendor patches for Oracle and NetApp products that bundle httpd.
- If mod_session is not required, disable it to remove the vulnerable code path.
- Restrict or review proxy and origin-server trust relationships so untrusted origins cannot inject crafted SessionHeader values.
- Track downstream vendor advisories for bundled httpd components and patch them on the vendor timeline.
Detection
- Monitor httpd logs for crashes, restarts or abnormal termination that coincide with proxy or origin-server traffic.
- Inspect inbound SessionHeader values at proxies and reverse proxies for oversized or malformed content.
- Use heap integrity tooling or ASAN builds in test environments to catch out-of-bounds writes in mod_session handling.
- Correlate httpd process crash telemetry with upstream origin server addresses to identify a malicious or compromised origin.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-26691 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-26691), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.