high CVSS 7.5

CVE-2026-56153·Apache vulnerability

Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Severity
high
Software
Apache
Fixed in
2.4.69
Published
2026-10-01

Affected versions

From: 2.4.0

Until: 2.4.69

Fixed in: 2.4.69

How to fix this CVE

Upgrade Apache HTTP Server to version 2.4.69 or later to patch the out-of-bounds write flaw in mod_charset_lite. This module processes character set encoding transformations; the vulnerability allows memory corruption when handling malformed charset directives. Immediate patching is recommended for production servers, particularly those exposing mod_charset_lite functionality.

sudo dnf update httpd httpd-core httpd-devel

Defensia detects this vulnerability

How to check if you are affected

  1. Run 'apache2ctl -v' or 'httpd -v' to confirm the installed Apache version; vulnerable versions are 2.4.0–2.4.68
  2. Check if mod_charset_lite is loaded by running 'apache2ctl -M | grep charset_lite' (Ubuntu/Debian) or 'httpd -M | grep charset_lite' (RHEL/CentOS); if listed, the module is active
  3. Search Apache error and access logs for unusual encoding-related errors or character set conversion failures: grep -i 'charset\|encoding\|iconv' /var/log/apache2/error.log /var/log/httpd/error_log
  4. After patching, verify the new version with 'apache2ctl -v' or 'httpd -v' and confirm it reports version 2.4.69 or higher

FAQ

What is CVE-2026-56153?

CVE-2026-56153 is an out-of-bounds write vulnerability in Apache's mod_charset_lite module that can trigger memory corruption when the module processes requests with specially crafted charset encoding parameters. This flaw has a CVSS score of 7.5 due to its potential for confidentiality impact.

Is CVE-2026-56153 being actively exploited?

No, according to CISA's Known Exploited Vulnerabilities catalog, CVE-2026-56153 is not currently being actively exploited in the wild, and no public exploit code has been released.

What versions of Apache are affected by CVE-2026-56153?

Apache HTTP Server versions 2.4.0 through 2.4.68 are vulnerable. Version 2.4.69 and later contain the necessary fix.

How do I check if my server is vulnerable to CVE-2026-56153?

Run 'apache2ctl -v' or 'httpd -v' to display your installed version. If it reports anything from 2.4.0 to 2.4.68 AND 'apache2ctl -M | grep charset_lite' returns the module, your server is vulnerable.

Does Defensia detect CVE-2026-56153?

Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2026-56153 will appear in your dashboard with remediation steps.

Related Apache CVEs

CVE-2024-38476CVSS 9.8Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
CVE-2024-38474CVSS 9.8Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.
CVE-2026-28780CVSS 9.8Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
CVE-2025-23048CVSS 9.1In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected when mod_ssl is configured for multiple virtual hosts, with each restricted to a different set of trusted client certificates (for example with a different SSLCACertificateFile/Path setting). In such a case, a client trusted to access one virtual host may be able to access another virtual host, if SSLStrictSNIVHostCheck is not enabled in either virtual host.
CVE-2024-38475CVSS 9.1Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected.  Some unsafe RewiteRules will be broken by this change and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained.

References

Track CVEs across your fleet automatically

Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-56153. Free for 1 server.

Get started free