News

Apache HTTP/2 shared buffer becomes a wild write

Louis Stowasser
Louis Stowasser
Monday 5 October 2026
Apache HTTP/2 shared buffer becomes a wild write
Apache HTTP/2 shared buffer becomes a wild write

CVE-2026-57941 is a memory-safety flaw in Apache HTTP Server’s mod_http2, the component that lets the widely deployed open-source web server speak HTTP/2. Apache sits in front of public sites and applications, terminates TLS, reverse-proxies traffic and serves internal systems too; hosting providers, enterprises, schools, research institutions and public-sector organisations all run it.

The affected code shares a temporary bucket brigade — Apache’s in-memory chain of data buffers — across an HTTP/2 session. Re-entrant processing can enter that code again before the first operation has finished, leaving the shared session->bbtmp buffer in the wrong lifetime state. The result is a use-after-free and, in Apache’s wording, a wild write: subsequent work may write through memory that has already been released or repurposed.

A network-facing bug without a published trigger

Affected releases span Apache HTTP Server 2.4.0 through 2.4.68. The supplied CVSS 3.1 assessment is 9.8, with network access, no privileges and no user interaction, and assigns high confidentiality, integrity and availability impact. That makes an HTTP/2-enabled, remotely reachable server the obvious patching priority.

Still, the impact needs careful wording. Apache rates the issue moderate, while the CISA ADP assessment shown by NVD assigns 9.8; Amazon Linux has published a lower, separate assessment. Apache identifies memory corruption, but does not say remote code execution has been demonstrated, and its advisory does not provide the request sequence required to trigger the re-entrancy. A wild write can plausibly enable a crash or worse depending on process and memory conditions, but a public exploit has not established that outcome.

As of October 5, 2026, no exploitation in the wild, victim, campaign or named actor could be confirmed. CISA’s SSVC contribution reports exploitation as none, and the CVE is absent from the Known Exploited Vulnerabilities catalogue data. No public proof of concept or working exploit has surfaced either; the available public tracking likewise reports none here.

Upgrade to 2.4.69, then verify the package actually changed

Apache fixed CVE-2026-57941 in 2.4.69, released October 1, 2026. The upstream patch replaces the session-wide temporary brigade with one local to the callback, so a nested operation does not reuse the same object:

-    status = h2_stream_read_to(stream, session->bbtmp, &len, &eos);
+    bb = apr_brigade_create(session->pool,
+                                                session->c1->bucket_alloc);
+    status = h2_stream_read_to(stream, bb, &len, &eos);
-    status = h2_c1_io_append(&session->io, session->bbtmp);
-    apr_brigade_cleanup(session->bbtmp);
+    status = h2_c1_io_append(&session->io, bb);
+    apr_brigade_destroy(bb);

The wider change also adds cleanup guards. Operators should upgrade to 2.4.69 or obtain their vendor’s backport, confirm the installed build rather than assuming an OS package is current, restart affected workers, and test HTTP/2 traffic through reverse proxies and virtual hosts. If HTTP/2 is not required, disabling mod_http2 can reduce exposure while an approved package is pending, but it is not a substitute for patching.

This is also a release-level maintenance job: 2.4.69 fixes other issues, including CVE-2026-59797 and CVE-2026-56154, among them. Apache’s release advisory is the authority for upstream status. Track the servers you actually operate with SecAlerts, which monitors an organisation’s software stack and alerts on new vulnerabilities affecting the products it runs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203