CVE-2026-57941
CVSS 9.8 CRITICAL: use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue…
Vulnerabilities · 4h ago
The Apache Software Foundation released Apache HTTP Server 2.4.69 to fix 20 vulnerabilities in the 2.4.x line, including 3 critical and 13 high-severity issues. INCIBE-CERT and CSIRT Italia both said the affected range runs through 2.4.68.
Several of the bugs live only in specific modules or when particular directives are enabled. INCIBE-CERT says the critical flaws include use-after-free issues in mod_http2 and mod_rewrite, plus a mod_ssl privilege problem tied to .htaccess use, so the same version can be exposed on one server and not on another depending on local configuration.
For operators, the lasting point is that version numbers alone do not tell the whole exposure story. If Apache sits behind module-heavy deployments or allows .htaccess, the vulnerable surface depends on what is loaded and enabled, not just on the package version.
CVSS 9.8 CRITICAL: use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue…
CVSS 9.8 CRITICAL: use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This…
CVSS 9.8 CRITICAL: improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related…
2 sources covering this story
Risolte vulnerabilità in Apache HTTP Server
Aggiornamenti di sicurezza sanano diverse vulnerabilità presenti in Apache HTTP Server, di cui 3 con gravità "critica" e 13 con gravità "alta".
Múltiples vulnerabilidades en HTTP Server de Apache
Apache Software Foundation ha publicado 20 vulnerabilidades: 3 de ellas de severidad círtica que, en c
Part of the PlainSec briefing for 2026-10-02