Heap underflow in Apache HTTP Server ap_regname via crafted regular expressions
CVE-2026-44631 is a buffer underwrite / heap underflow vulnerability in Apache HTTP Server affecting versions 2.4.0 through 2.4.67. The issue is described by Apache as a heap underflow in ap_regname caused by signed char overflow, and is triggered by crafted regular expressions present in server configuration. Successful triggering can cause memory corruption during processing of the affected regular-expression handling path in configuration parsing or use.
Are you exposed to this one?
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
Impact, mitigation & remediation
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
Impact
What an attacker gets, and what they’ve been doing with it.
Mitigation
If you can’t patch tonight, do this now.
ap_regname path. Restrict who can modify server configuration, audit included configuration files and templates for attacker-influenced regex content, and deploy the fixed release as soon as operationally possible. No complete mitigation short of upgrading is provided in the source material.Remediation
Patch, then assume compromise.
r1935015 as the fix in the 2.4.x branch.Exploits
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Recent activity
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A char overflow / heap underwrite vulnerability in Apache HTTP Server triggered during parsing of custom regular expressions.
A buffer underwrite vulnerability in Apache HTTP Server triggered by crafted regular expressions in the configuration, affecting versions 2.4.0 through 2.4.67.
Apache HTTP Server vulnerability fixed in version 2.4.68; exact flaw details are unclear from the corrupted text.
Apache HTTP Server vulnerability related to handling specially crafted requests and configurations.
The version that knows your environment.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.