CVE-2026-56154·Apache vulnerability
Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
- Severity
- critical
- Software
- Apache
- Fixed in
- 2.4.69
- Published
- 2026-10-01
Affected versions
From: 2.4.0
Until: 2.4.69
Fixed in: 2.4.69
How to fix this CVE
Upgrade Apache HTTP Server to version 2.4.69 or later to remediate this critical use-after-free vulnerability in mod_rewrite's lookahead functionality. Organizations running affected versions (2.4.0–2.4.68) should prioritize this update, as the vulnerability can lead to server crashes or potential code execution when rewrite rules leverage lookahead assertions. Apply patches through your distribution's package manager or manually compile the latest Apache release.
sudo dnf update httpdDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check Apache version with `apache2ctl -v` (Debian/Ubuntu) or `httpd -v` (RHEL/CentOS) and confirm it is 2.4.69 or later
- Step 2: Verify mod_rewrite is loaded by running `apache2ctl -M | grep rewrite` and check for RewriteRule or RewriteCond directives using LA-U: lookahead patterns in `/etc/apache2/sites-enabled/` or `/etc/httpd/conf.d/`
- Step 3: Search Apache error logs for segmentation faults or memory corruption messages: `grep -i 'segfault\|abort\|use after free' /var/log/apache2/error.log /var/log/httpd/error_log`
- Step 4: After patching, restart Apache with `sudo systemctl restart apache2` (Debian/Ubuntu) or `sudo systemctl restart httpd` (RHEL/CentOS) and confirm successful startup with `systemctl status apache2` or `systemctl status httpd`
FAQ
What is CVE-2026-56154?
CVE-2026-56154 is a use-after-free vulnerability in Apache HTTP Server's mod_rewrite module that occurs when processing lookahead assertions (LA-U:HTTP:...). This memory safety defect can cause the web server to crash or potentially allow remote code execution if an attacker crafts malicious HTTP requests targeting rewrite rules that use lookahead patterns.
Is CVE-2026-56154 being actively exploited?
No, CVE-2026-56154 is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and no public exploits are available. However, its critical CVSS 9.8 score warrants immediate patching regardless of active exploitation status.
What versions of Apache are affected by CVE-2026-56154?
Apache HTTP Server versions 2.4.0 through 2.4.68 are vulnerable. Version 2.4.69 and later contain the fix.
How do I check if my server is vulnerable to CVE-2026-56154?
Run `httpd -v` or `apache2ctl -v` to retrieve your installed version. If the output shows any version from 2.4.0 to 2.4.68, your server is vulnerable. Additionally, verify mod_rewrite is enabled and contains lookahead assertions with `apache2ctl -M | grep rewrite` and inspect your rewrite configuration files.
Does Defensia detect CVE-2026-56154?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2026-56154 will appear in your dashboard with remediation steps.
Related Apache CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-56154. Free for 1 server.
Get started free