Use After Free Vulnerability in Apache HTTP Server Affecting Shared Sessions
CVE-2026-57941

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
1 October 2026

What is CVE-2026-57941?

A use after free vulnerability has been identified in the Apache HTTP Server, specifically within the mod_http2 module. This flaw can be triggered via re-entrancy in shared sessions, potentially allowing an attacker to exploit this oversight. Affected versions range from 2.4.0 to 2.4.68, highlighting the need for administrators to update to protect their systems from possible exploitation.

Affected Version(s)

Apache HTTP Server 2.4.0 <= 2.4.68

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lucian Nitescu
Simon Kappel
Gianluca Danesin, Altervista
.