{
  "from_raw": "Eric Covener <covener@apache.org>",
  "from": "Eric Covener <co...@apache.org>",
  "gravatar": "ee9bd44fca004cd144fce0d972679406",
  "to": "an...@apache.org,\n de...@httpd.apache.org",
  "subject": "CVE-2026-59685: Apache HTTP Server: Out-of-Bounds Write in ap_directory_walk() Canonical-Name Rewrite on CASE_BLIND_FILESYSTEM",
  "message-id": "<7505502f-5d70-2a00-5db1-bca67586e515@apache.org>",
  "mid": "oqyomf60j1yml29f43mgy7ztdnvt8twc",
  "permalinks": [
    "oqyomf60j1yml29f43mgy7ztdnvt8twc",
    "re239e34987454ef6f9de1134e12f3b0698edff4b7d6e964e1efd0357@<announce.apache.org>"
  ],
  "dbid": "ffa2d2f563018645b3a9b6df91681993bdcb5cfad01eb349d0204003bf0a73bd",
  "cc": "de...@httpd.apache.org",
  "epoch": 1790878409,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/10/01 18:13:29",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: moderate \n\nAffected versions:\n\n- Apache HTTP Server 2.4.0 through 2.4.68\n\nDescription:\n\nOut-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.\n\nCredit:\n\nDhiraj Mishra (finder)\nFeng Ning (innora.ai / Innora Security Research) (finder)\n\nReferences:\n\nhttps://httpd.apache.org/security/vulnerabilities_24.html\nhttps://httpd.apache.org/\nhttps://www.cve.org/CVERecord?id=CVE-2026-59685\n\nTimeline:\n\n2026-05-06: reported\n2026-10-01: fixed in 2.4.x by r1938670\n2026-10-01: 2.4.69 released\n\n",
  "body_short": "Severity: moderate \n\nAffected versions:\n\n- Apache HTTP Server 2.4.0 through 2.4.68\n\nDescription:\n\nOut-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 name",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 3288,
  "id": "oqyomf60j1yml29f43mgy7ztdnvt8twc"
}