CVE-2026-48913: Apache HTTP Server: mod_http2 memory corruption when file handles exhausted
Last updated 20 July 2026
Other sources
Use After Free vulnerability in Apache HTTP Server module modhttp2 when file handles are already exhausted.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.67-1~deb11u3Fixed in 2.4.68-1~deb12u1Fixed in 2.4.68-1~deb13u1Fixed in 2.4.68-1 - Upgrade
Upgrade
Apache HTTP Server (mod_http2)to a version that resolves this vulnerability.Fixed in 2.4.55 through 2.4.67 - Compensating control
Mitigate by ensuring file handles are not exhausted (monitor and increase OS/file-handle limits so mod_http2 does not encounter exhausted file handles).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48913?
CVE-2026-48913 has a risk score of 60, indicating a moderate severity level.
How do I fix CVE-2026-48913?
To mitigate CVE-2026-48913, upgrade the Apache HTTP Server to version 2.4.68 or later.
What causes CVE-2026-48913?
CVE-2026-48913 is caused by a Use After Free vulnerability in the mod_http2 module when file handles are exhausted.
Which versions of Apache HTTP Server are affected by CVE-2026-48913?
CVE-2026-48913 affects Apache HTTP Server versions from 2.4.55 to 2.4.67.
Is there a workaround for CVE-2026-48913?
Currently, there are no official workarounds for CVE-2026-48913 apart from upgrading to a patched version.