critical CVSS 9.8

CVE-2026-57941·Apache vulnerability

Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Severity
critical
Software
Apache
Fixed in
2.4.69
Published
2026-10-01

Affected versions

From: 2.4.0

Until: 2.4.69

Fixed in: 2.4.69

How to fix this CVE

Update Apache HTTP Server to version 2.4.69 or later to remediate this critical use-after-free vulnerability in mod_http2. The vulnerability stems from improper handling of shared session buffer re-entrancy, which can lead to remote code execution without authentication. Administrators should prioritize this update as it affects all versions from 2.4.0 through 2.4.68 and poses a severe risk to production systems.

sudo dnf update httpd httpd-core httpd-devel --assumeyes

Defensia detects this vulnerability

How to check if you are affected

  1. Check installed Apache version: apache2ctl -v (or httpd -v on RHEL/CentOS). Verify if version is < 2.4.69
  2. Confirm mod_http2 is enabled: apache2ctl -M | grep http2 (or httpd -M on RHEL). If http2_module appears, the vulnerable component is loaded
  3. Search error and access logs for HTTP/2 protocol errors: grep -i 'h2\|http/2' /var/log/apache2/error.log | grep -i 'reentrant\|use.after.free\|segfault'
  4. After patching, verify the fix: apache2ctl -v should show 2.4.69 or higher, and systemctl restart apache2 should complete without errors

FAQ

What is CVE-2026-57941?

CVE-2026-57941 is a critical use-after-free vulnerability in Apache HTTP Server's mod_http2 module that occurs when shared session buffers are accessed with improper re-entrancy controls, potentially allowing remote code execution without authentication.

Is CVE-2026-57941 being actively exploited?

According to CISA KEV data, CVE-2026-57941 is not currently listed as actively exploited in the wild, though no public exploits exist yet. However, the critical CVSS score of 9.8 means it poses an immediate risk once exploitation techniques become available.

What versions of Apache are affected by CVE-2026-57941?

Apache HTTP Server versions 2.4.0 through 2.4.68 are vulnerable. The vulnerability is remediated in version 2.4.69 and later.

How do I check if my server is vulnerable to CVE-2026-57941?

Run 'apache2ctl -v' (or 'httpd -v' on RHEL/CentOS) and check if the version is less than 2.4.69. Additionally, verify mod_http2 is enabled with 'apache2ctl -M | grep http2' (or 'httpd -M' on RHEL). If both conditions are true, your system is vulnerable.

Does Defensia detect CVE-2026-57941?

Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2026-57941 will appear in your dashboard with remediation steps.

Related Apache CVEs

CVE-2021-42013CVSS 10It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier versions.
CVE-2021-41773CVSS 10A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.
CVE-2026-59797CVSS 9.8Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
CVE-2024-38476CVSS 9.8Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
CVE-2024-38474CVSS 9.8Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.

References

Track CVEs across your fleet automatically

Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-57941. Free for 1 server.

Get started free