EIP-2026-103551

PRE-CVE

Mod_NTLM 0.x - Authorisation Heap Overflow

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103551. PoCs published by Matthew Murphy.

AI-analyzed exploit summary The provided text describes a heap overflow vulnerability in the mod_ntlm Apache module, but the included code snippet is merely an example HTTP request with an Authorization header and does not constitute a functional exploit. It lacks executable exploit code or a proof-of-concept payload.

Description

Mod_NTLM 0.x - Authorisation Heap Overflow

Exploits (1)

exploitdb WRITEUP VERIFIED
by Matthew Murphy · textdosmultiple
https://www.exploit-db.com/exploits/22512

The provided text describes a heap overflow vulnerability in the mod_ntlm Apache module, but the included code snippet is merely an example HTTP request with an Authorization header and does not constitute a functional exploit. It lacks executable exploit code or a proof-of-concept payload.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: mod_ntlm <= v0.4 for Apache 1.3 and mod_ntlmv2 version 0.1 for Apache 2.0
No auth needed
Prerequisites: Network access to the target Apache server · mod_ntlm or mod_ntlmv2 module enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026