CVE-2026-57941: Apache HTTP Server: mod_http2 use-after-free / wild write via shared session->bbtmp re-entrancy
Published Oct 1, 2026
·Updated
Use After Free vulnerability in Apache HTTP Server's modhttp2 via shared session->bbtmp re-entrancy
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Affected Software
1 affected component
Apache HTTP Server>=2.4.0<=2.4.68
Event History
Oct 1, 2026
CVE Published
via MITRE·04:06 PM
Data Sourced
via MITRE·04:06 PM
DescriptionWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are within the affected version range?
Apache HTTP Server versions from 2.4.0 through 2.4.68 are affected according to the available information.
2
Is exploitation tied to a particular Apache module?
The issue is in mod_http2, so deployments using that module are the relevant exposure area.