Description
Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy



This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Published: 2026-10-01
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Memory corruption due to use‑after‑free in mod_http2
Action: Patch or Disable
AI Analysis

Impact

The Apache HTTP Server mod_http2 module contains a use‑after‑free vulnerability that can lead to arbitrary memory manipulation. The flaw arises when concurrent access to the shared session->bbtmp data structure triggers a re‑entrancy bug, allowing an attacker to corrupt server memory or cause a crash. This type of vulnerability can compromise the integrity of running processes and potentially expose sensitive data if memory corruption results in information leakage.

Affected Systems

It affects Apache HTTP Server versions 2.4.0 through 2.4.68 whenever the mod_http2 module is built and loaded. The vulnerability is present in official releases from the Apache Software Foundation and any custom builds that enable HTTP/2 support.

Risk and Exploitability

The CVSS v3.1 base score is 9.8, indicating a critical severity. EPSS is not available and the flaw is not listed in the CISA KEV catalog. The description does not explicitly state an exploitation method; however, the flaw is reachable via HTTP/2 traffic and the likely attack vector is inferred to be network‑based. An attacker could submit crafted HTTP/2 requests to trigger the re‑entrancy and provoke memory corruption, which may lead to denial of service or more serious compromise depending on the environment and privileges of the running process.

Generated by OpenCVE AI on October 1, 2026 at 22:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache HTTP Server to a patched release (≥2.4.69) that resolves the mod_http2 re‑entrancy issue.
  • If an immediate upgrade is not feasible, disable the HTTP/2 module by removing or commenting out the LoadModule http2_module directive in the server configuration.
  • Apply continuous monitoring by inspecting HTTP/2 request logs for abnormal patterns, and consider limiting the use of HTTP/2 to trusted clients.

Generated by OpenCVE AI on October 1, 2026 at 22:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
References

Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache apache Http Server
Vendors & Products Apache
Apache apache Http Server

Thu, 01 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Title Apache HTTP Server: mod_http2 use-after-free / wild write via shared session->bbtmp re-entrancy
Weaknesses CWE-416
References

Subscriptions

Apache Apache Http Server
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-01T20:09:25.619Z

Reserved: 2026-06-26T13:34:41.733Z

Link: CVE-2026-57941

cve-icon Vulnrichment

Updated: 2026-10-01T20:09:25.619Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-01T17:17:27.457

Modified: 2026-10-01T21:17:22.607

Link: CVE-2026-57941

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T23:00:20Z

Weaknesses