Out-of-Bounds Write Vulnerability in Apache HTTP Server by Apache Software Foundation
CVE-2026-56153

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
1 October 2026

What is CVE-2026-56153?

An out-of-bounds write vulnerability has been identified in the mod_charset_lite module of the Apache HTTP Server. This flaw allows an attacker to execute malicious code by manipulating memory outside the intended bounds, potentially leading to arbitrary code execution or application crashes. This issue impacts all versions of Apache HTTP Server from 2.4.0 through 2.4.68, necessitating prompt updates to ensure the security of web applications using this server.

Affected Version(s)

Apache HTTP Server 2.4.0 <= 2.4.68

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bartlomiej Dmitruk at striga.ai
Masumi Tanaka
.