PT-2026-103928 · Apache · Apache Http Server

·

CVE-2026-56154

·

Published

2026-10-01

·

Updated

2026-10-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.0 through 2.4.68
Description A Use After Free issue exists in the mod rewrite module when utilizing the lookahead feature %{LA-U:HTTP:...}. Use After Free is a memory corruption flaw that occurs when an application continues to use a pointer after it has been freed, which can lead to crashes or arbitrary code execution.
Recommendations Update Apache HTTP Server to a version later than 2.4.68.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56154

Affected Products

Apache Http Server