https://seclists.org/oss-sec/2026/q2/844: CVE-2026-48913: Apache HTTP Server: mod_http2 memory corruption when file handles exhausted
Published Jun 8, 2026
·Updated
Affected Software
1 affected component
Apache HTTP Server>=2.4.55<=2.4.67
Frequently Asked Questions
1
What is the severity of CVE-2026-48913?
The severity of CVE-2026-48913 is classified as low.
2
Which versions of Apache HTTP Server are affected by CVE-2026-48913?
CVE-2026-48913 affects Apache HTTP Server versions 2.4.55 through 2.4.67.
3
What is the impact of CVE-2026-48913?
CVE-2026-48913 is a Use After Free vulnerability that occurs when file handles are exhausted.
4
How do I fix CVE-2026-48913?
To fix CVE-2026-48913, upgrade to a version of Apache HTTP Server that is not affected, specifically to version 2.4.68 or later.
5
Who reported CVE-2026-48913?
CVE-2026-48913 was reported by Sam Lovejoy from IBM X-Force.