Vulnerability
Published 2026-10-01
Verified 2026-10-02

Apache HTTP Server 2.4.69 (1 Oct): mod_http2 UAF CVE-2026-57941 (Apache moderate; ADP CVSS 9.8) + 19 other fixes

Apache HTTP Server 2.4.69 was released 1 October 2026 fixing twenty vulnerabilities across httpd 2.4.x (vendor security page Fixed in 2.4.69). Headline issue CVE-2026-57941: use-after-free / wild write in mod_http2 via shared session->bbtmp re-entrancy affecting 2.4.0 through 2.4.68 — Apache rates moderate; CVE.org ADP / NVD Secondary CVSS 3.1 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H); CISA SSVC on NVD at publication: exploitation none, automatable yes, technical impact total. Other Apache-rated moderate issues in the same train include CVE-2026-42528 mod_dav shared lock overflow, CVE-2026-59685 Windows OOB write on 8.3 names, CVE-2026-63292 mod_vhost_alias stack overflow (Host header >8192 when VirtualDocumentRoot + raised LimitRequestFieldSize), and CVE-2026-93546 mod_dav_fs integer overflow. Remaining CVEs (42356, 46729, 47360, 48005, 56153, 56154, 56449, 58415, 59797, 63045, 63686, 63718, 73636, 73637, 79768) are Apache-rated low (CGI redirect handler, heartmonitor DoS, session cookie leak, digest auth issues, charset/rewrite/proxy_html, dav_fs property read, SSLRequire, FTP PASV, xml2enc, uwsgi smuggling, userdir path equivalence). Finders include Lucian Nitescu, Simon Kappel, Gianluca Danesin/Altervista and others per Apache acknowledgements. No in-the-wild claim on the vendor page. Primary: Apache httpd 2.4 vulnerabilities page; oss-security 1 Oct.

Product
Apache HTTP Server (httpd 2.4.x; mod_http2 / mod_dav / mod_vhost_alias and others)
Versions
Affected (CVE-2026-57941 and most of the 2.4.69 set): 2.4.0 through 2.4.68 (some CVEs narrower, e.g. 42356: 2.4.60–2.4.68; 63718: 2.4.30–2.4.68). Fixed: 2.4.69.
CVSS
(CVSS 3.1 Critical; CVE.org ADP / NVD Secondary for CVE-2026-57941 — Apache vendor severity: moderate)
Exploited in Australia?
unknown
Patch to
Upgrade to Apache HTTP Server 2.4.69 (or later). Prioritise internet-facing hosts with mod_http2, WebDAV (mod_dav/mod_dav_fs), VirtualDocumentRoot, and Windows CASE_BLIND_FILESYSTEM deployments. Distro packages: apply vendor backports when available.

Primary: Apache HTTP Server — Fixed in 2.4.69 (released 1 Oct 2026) · Vendor: Apache HTTP Server Project — security/vulnerabilities_24.html · CVE: CVE-2026-57941, CVE-2026-42528, CVE-2026-59685, CVE-2026-63292, CVE-2026-93546 · CVE.org — CVE-2026-57941 mod_http2 UAF (Apache moderate; ADP 9.8)

vulnerabilities network cloud