Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-57941: Apache HTTP Server may crash or be taken over
CVE-2026-57941 · published 9 days ago
Summary
Versions 2.4.0 through 2.4.68 of Apache HTTP Server can mishandle memory in the HTTP/2 module, which could let an attacker cause the server to stop working or execute their own code. This risk affects installations from the Apache Software Foundation as well as Debian, Ubuntu, Alpine, and BellSoft packages. Update to the newest Apache HTTP Server release as soon as possible to eliminate the issue.
What to do
- Update alpine apache2 to version 2.4.69-r0.
- Update bellsoft apache2 to version 2.4.69-r0.
- Update debian apache2 to version 2.4.69-1.
- Update apache to version 2.4.69.
- Update apache2 to version 2.4.69-r0.
- Update apache http_server to version 2.4.69 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | apache software foundation | apache http server | <= 2.4.68 |
| Debian:12 | debian | apache2 | All versions |
| Ubuntu:Pro:14.04:LTS | canonical | apache2 | All versions |
| Alpine:v3.21 | alpine | apache2 |
< 2.4.69-r0 Fix: upgrade to 2.4.69-r0
|
| Alpaquita:23 | bellsoft | apache2 |
>= 2.4.54-r2, < 2.4.69-r0 Fix: upgrade to 2.4.69-r0
|
| Alpaquita:25 | bellsoft | apache2 |
>= 2.4.63-r0, < 2.4.69-r0 Fix: upgrade to 2.4.69-r0
|
| Alpaquita:stream | bellsoft | apache2 |
>= 2.4.56-r0, < 2.4.69-r0 Fix: upgrade to 2.4.69-r0
|
| – | apache | http_server |
>= 2.4.0, < 2.4.69 cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* |
| Debian:14 | debian | apache2 |
< 2.4.69-1 Fix: upgrade to 2.4.69-1
|
| Bitnami | – | apache |
>= 2.4.0, < 2.4.69 Fix: upgrade to 2.4.69
|
| Alpine:v3.21 | – | apache2 |
< 2.4.69-r0 Fix: upgrade to 2.4.69-r0
|
Original advisory text
BELL-CVE-2026-57941
Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
References
- https://httpd.apache.org/security/vulnerabilities_24.html Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-57941 Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/10/01/19 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-57941 Third Party Advisory
- https://security.alpinelinux.org/vuln/CVE-2026-57941 Vendor Advisory
- https://docs.bell-sw.com/security/cves/CVE-2026-57941 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-57941 Third Party Advisory
- https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-57941 Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-57941 URL
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.8
Critical
Type
CWE-416Use After Free
Timeline
Published1 Oct 2026
Updated9 Oct 2026
First seen1 Oct 2026
Sources
CVE-2026-57941 · NVD
CVE-2026-57941 · MITRE
DEBIAN-CVE-2026-57941 · OSV
UBUNTU-CVE-2026-57941 · OSV
ALPINE-CVE-2026-57941 · OSV
BELL-CVE-2026-57941 · OSV
BIT-apache-2026-57941 · OSV
Track software like this
Free during beta