CVE-2026-48913
published 2026-06-08CVE-2026-48913: Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55…
PriorityP346high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.48%
38.5th percentile
Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted.
This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.4.55 < 2.4.68 | 2.4.68 |
| apache | httpd | — | — |
| apache_software_foundation | apache_http_server | 2.4.55 – 2.4.67 | — |
| ubuntu | apache2 | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
ghsa9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache HTTP Server up to 2.4.67 mod_http2 memory corruption (EUVD-2026-35101)
vuldb·2026-06-08·CVSS 7.3
CVE-2026-48913 [HIGH] Apache HTTP Server up to 2.4.67 mod_http2 memory corruption (EUVD-2026-35101)
A vulnerability classified as critical was found in Apache HTTP Server up to 2.4.67. This issue affects some unknown processing of the component mod_http2. Executing a manipulation can lead to memory corruption.
This vulnerability appears as CVE-2026-48913. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
GHSA
Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted.
ghsa_unreviewed·2026-06-08
CVE-2026-48913 [HIGH] CWE-416 Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted.
Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted.
This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.
GHSA
Apache CXF: Untrusted JMS configuration can lead to RCE
ghsa·2026-05-26·CVSS 9.8
CVE-2026-44417 [CRITICAL] CWE-20 Apache CXF: Untrusted JMS configuration can lead to RCE
Apache CXF: Untrusted JMS configuration can lead to RCE
The fix for CVE-2025-48913: `Apache CXF: Untrusted JMS configuration can lead to RCE` was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 5.3
CVE-2026-34032 [MEDIUM] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server
incorrectly handled certain memory operations in mod_authn_socache. A
remote attacker could possibly use this issue to cause a denial of service.
(CVE-2026-33007)
Haruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache
HTTP Server had an HTTP response splitting vulnerability in multiple
modules when used with untrusted or compromised backend servers. An
attacker could possibly use this issue to inject arbitrary HTTP headers.
(CVE-2026-33523)
Elhanan Haenel discovered that Apache HTTP Server incorrectly handled
certain memory operations in mod_proxy_ajp. A remote attacker could
possibly use this i
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-07-08·CVSS 9.8
CVE-2026-44119 [CRITICAL] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
It was discovered that Apache HTTP Server's mod_ldap module incorrectly
handled memory when processing per-directory configurations. An attacker
could use this issue to cause the server to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2026-29167)
It was discovered that Apache HTTP Server's mod_proxy_ftp module
incorrectly handled HTML generation for FTP directory listings. A remote
attacker could possibly use this issue to inject arbitrary web script or
HTML. (CVE-2026-29170)
It was discovered that Apache HTTP Server's mod_proxy_html module
incorrectly handled certain content from an untrusted backend. A remote
attacker could possibly use this
Red Hat
httpd: mod_http2: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service.
vendor_redhat·2026-06-08·CVSS 7.3
CVE-2026-48913 [HIGH] CWE-825 httpd: mod_http2: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service.
httpd: mod_http2: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service.
Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted.
This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.
A flaw was found in the Apache HTTP Server's mod_http2 module. This vulnerability, known as a Use After Free, occurs when the server's file handles are exhausted. An attacker could potentially exploit this to cause a denial of service or, in some cases, execute arbitrary code, leading to system compromise.
Statement: A use-after-free vulnerability exists in the Apache HTTP Server mod_http2 module when system file handles are exhausted. A remote attacker could trigger this flaw via HTTP
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-48913 httpd: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service. [fedora-all]
bugzilla·2026-07-01·CVSS 7.3
CVE-2026-48913 [HIGH] CVE-2026-48913 httpd: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service. [fedora-all]
CVE-2026-48913 httpd: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted.
This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.
Bugzilla
CVE-2026-48913 mod_http2: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service. [fedora-all]
bugzilla·2026-07-01·CVSS 7.3
CVE-2026-48913 [HIGH] CVE-2026-48913 mod_http2: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service. [fedora-all]
CVE-2026-48913 mod_http2: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted.
This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.
Bugzilla
CVE-2026-48913 httpd: mod_http2: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service.
bugzilla·2026-06-08·CVSS 7.3
CVE-2026-48913 [HIGH] CVE-2026-48913 httpd: mod_http2: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service.
CVE-2026-48913 httpd: mod_http2: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service.
Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted.
This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:34355 https://access.redhat.com/errata/RHSA-2026:34355
Bugzilla
CVE-2026-44417 org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Remote Code Execution via untrusted JMS configuration
bugzilla·2026-05-22·CVSS 9.8
CVE-2026-44417 [CRITICAL] CVE-2026-44417 org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Remote Code Execution via untrusted JMS configuration
CVE-2026-44417 org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Remote Code Execution via untrusted JMS configuration
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
2026-06-08
Published