critical CVSS 9.8

CVE-2026-56154·Apache vulnerability

Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Severity
critical
Software
Apache
Fixed in
2.4.69
Published
2026-10-01

Affected versions

From: 2.4.0

Until: 2.4.69

Fixed in: 2.4.69

How to fix this CVE

Upgrade Apache HTTP Server to version 2.4.69 or later to remediate this critical use-after-free vulnerability in mod_rewrite's lookahead functionality. Organizations running affected versions (2.4.0–2.4.68) should prioritize this update, as the vulnerability can lead to server crashes or potential code execution when rewrite rules leverage lookahead assertions. Apply patches through your distribution's package manager or manually compile the latest Apache release.

sudo dnf update httpd

Defensia detects this vulnerability

How to check if you are affected

  1. Step 1: Check Apache version with `apache2ctl -v` (Debian/Ubuntu) or `httpd -v` (RHEL/CentOS) and confirm it is 2.4.69 or later
  2. Step 2: Verify mod_rewrite is loaded by running `apache2ctl -M | grep rewrite` and check for RewriteRule or RewriteCond directives using LA-U: lookahead patterns in `/etc/apache2/sites-enabled/` or `/etc/httpd/conf.d/`
  3. Step 3: Search Apache error logs for segmentation faults or memory corruption messages: `grep -i 'segfault\|abort\|use after free' /var/log/apache2/error.log /var/log/httpd/error_log`
  4. Step 4: After patching, restart Apache with `sudo systemctl restart apache2` (Debian/Ubuntu) or `sudo systemctl restart httpd` (RHEL/CentOS) and confirm successful startup with `systemctl status apache2` or `systemctl status httpd`

FAQ

What is CVE-2026-56154?

CVE-2026-56154 is a use-after-free vulnerability in Apache HTTP Server's mod_rewrite module that occurs when processing lookahead assertions (LA-U:HTTP:...). This memory safety defect can cause the web server to crash or potentially allow remote code execution if an attacker crafts malicious HTTP requests targeting rewrite rules that use lookahead patterns.

Is CVE-2026-56154 being actively exploited?

No, CVE-2026-56154 is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and no public exploits are available. However, its critical CVSS 9.8 score warrants immediate patching regardless of active exploitation status.

What versions of Apache are affected by CVE-2026-56154?

Apache HTTP Server versions 2.4.0 through 2.4.68 are vulnerable. Version 2.4.69 and later contain the fix.

How do I check if my server is vulnerable to CVE-2026-56154?

Run `httpd -v` or `apache2ctl -v` to retrieve your installed version. If the output shows any version from 2.4.0 to 2.4.68, your server is vulnerable. Additionally, verify mod_rewrite is enabled and contains lookahead assertions with `apache2ctl -M | grep rewrite` and inspect your rewrite configuration files.

Does Defensia detect CVE-2026-56154?

Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2026-56154 will appear in your dashboard with remediation steps.

Related Apache CVEs

CVE-2021-42013CVSS 10It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier versions.
CVE-2021-41773CVSS 10A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.
CVE-2024-38476CVSS 9.8Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
CVE-2024-38474CVSS 9.8Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.
CVE-2026-59797CVSS 9.8Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

References

Track CVEs across your fleet automatically

Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-56154. Free for 1 server.

Get started free