Security advisories in the AI and data stack

Severe, 6 weeks2979Projects319

Apache HTTP Server: use after free

Critical9.8CVE-2026-57941 · Published Oct 1, 2026 · updated Oct 5, 2026

Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Affected versions

PackageAffectedFixed in
Apache HTTP Server
Product
>= 2.4.0, <= 2.4.68No fix yet
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache HTTP Server: integer overflow
High8.8Oct 1
Apache HTTP Server: use after free
High7.3Oct 1
Path equivalence: '/./'
Medium5.3Oct 1
Apache HTTP Server: request smuggling
High7.5Oct 1
Apache HTTP Server: authentication bypass
High8.1Oct 1
Apache HTTP Server: exposed files
Medium5.3Oct 1