CLEANSTART-2026-UC87477

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-UC87477.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2026-UC87477
Upstream
Published
2026-10-09T00:49:53Z
Modified
2026-10-09T01:00:22Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes
Details

Security vulnerability affects the apache2 package. If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes.

References

Affected packages

CleanStart / apache2

Package

Name
apache2
Purl
pkg:apk/cleanstart/apache2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.4.53-r0

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-UC87477.json"