CVE-2026-56153·Apache vulnerability
Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
- Severity
- high
- Software
- Apache
- Fixed in
- 2.4.69
- Published
- 2026-10-01
Affected versions
From: 2.4.0
Until: 2.4.69
Fixed in: 2.4.69
How to fix this CVE
Upgrade Apache HTTP Server to version 2.4.69 or later to patch the out-of-bounds write flaw in mod_charset_lite. This module processes character set encoding transformations; the vulnerability allows memory corruption when handling malformed charset directives. Immediate patching is recommended for production servers, particularly those exposing mod_charset_lite functionality.
sudo dnf update httpd httpd-core httpd-develDefensia detects this vulnerability
How to check if you are affected
- Run 'apache2ctl -v' or 'httpd -v' to confirm the installed Apache version; vulnerable versions are 2.4.0–2.4.68
- Check if mod_charset_lite is loaded by running 'apache2ctl -M | grep charset_lite' (Ubuntu/Debian) or 'httpd -M | grep charset_lite' (RHEL/CentOS); if listed, the module is active
- Search Apache error and access logs for unusual encoding-related errors or character set conversion failures: grep -i 'charset\|encoding\|iconv' /var/log/apache2/error.log /var/log/httpd/error_log
- After patching, verify the new version with 'apache2ctl -v' or 'httpd -v' and confirm it reports version 2.4.69 or higher
FAQ
What is CVE-2026-56153?
CVE-2026-56153 is an out-of-bounds write vulnerability in Apache's mod_charset_lite module that can trigger memory corruption when the module processes requests with specially crafted charset encoding parameters. This flaw has a CVSS score of 7.5 due to its potential for confidentiality impact.
Is CVE-2026-56153 being actively exploited?
No, according to CISA's Known Exploited Vulnerabilities catalog, CVE-2026-56153 is not currently being actively exploited in the wild, and no public exploit code has been released.
What versions of Apache are affected by CVE-2026-56153?
Apache HTTP Server versions 2.4.0 through 2.4.68 are vulnerable. Version 2.4.69 and later contain the necessary fix.
How do I check if my server is vulnerable to CVE-2026-56153?
Run 'apache2ctl -v' or 'httpd -v' to display your installed version. If it reports anything from 2.4.0 to 2.4.68 AND 'apache2ctl -M | grep charset_lite' returns the module, your server is vulnerable.
Does Defensia detect CVE-2026-56153?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2026-56153 will appear in your dashboard with remediation steps.
Related Apache CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-56153. Free for 1 server.
Get started free