CVE-2026-57941·Apache vulnerability
Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
- Severity
- critical
- Software
- Apache
- Fixed in
- 2.4.69
- Published
- 2026-10-01
Affected versions
From: 2.4.0
Until: 2.4.69
Fixed in: 2.4.69
How to fix this CVE
Update Apache HTTP Server to version 2.4.69 or later to remediate this critical use-after-free vulnerability in mod_http2. The vulnerability stems from improper handling of shared session buffer re-entrancy, which can lead to remote code execution without authentication. Administrators should prioritize this update as it affects all versions from 2.4.0 through 2.4.68 and poses a severe risk to production systems.
sudo dnf update httpd httpd-core httpd-devel --assumeyesDefensia detects this vulnerability
How to check if you are affected
- Check installed Apache version: apache2ctl -v (or httpd -v on RHEL/CentOS). Verify if version is < 2.4.69
- Confirm mod_http2 is enabled: apache2ctl -M | grep http2 (or httpd -M on RHEL). If http2_module appears, the vulnerable component is loaded
- Search error and access logs for HTTP/2 protocol errors: grep -i 'h2\|http/2' /var/log/apache2/error.log | grep -i 'reentrant\|use.after.free\|segfault'
- After patching, verify the fix: apache2ctl -v should show 2.4.69 or higher, and systemctl restart apache2 should complete without errors
FAQ
What is CVE-2026-57941?
CVE-2026-57941 is a critical use-after-free vulnerability in Apache HTTP Server's mod_http2 module that occurs when shared session buffers are accessed with improper re-entrancy controls, potentially allowing remote code execution without authentication.
Is CVE-2026-57941 being actively exploited?
According to CISA KEV data, CVE-2026-57941 is not currently listed as actively exploited in the wild, though no public exploits exist yet. However, the critical CVSS score of 9.8 means it poses an immediate risk once exploitation techniques become available.
What versions of Apache are affected by CVE-2026-57941?
Apache HTTP Server versions 2.4.0 through 2.4.68 are vulnerable. The vulnerability is remediated in version 2.4.69 and later.
How do I check if my server is vulnerable to CVE-2026-57941?
Run 'apache2ctl -v' (or 'httpd -v' on RHEL/CentOS) and check if the version is less than 2.4.69. Additionally, verify mod_http2 is enabled with 'apache2ctl -M | grep http2' (or 'httpd -M' on RHEL). If both conditions are true, your system is vulnerable.
Does Defensia detect CVE-2026-57941?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2026-57941 will appear in your dashboard with remediation steps.
Related Apache CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-57941. Free for 1 server.
Get started free