CRITICAL 9.8 CVE-2026-56154 Published 1 Oct 2026

Apache HTTP Server mod_rewrite Use-After-Free Vulnerability

Worried this affects your website?

Apache HTTP Server contains a use-after-free vulnerability in its mod_rewrite module when using lookahead expressions such as %{LA-U:HTTP:...}.

This issue affects Apache HTTP Server versions from 2.4.0 through 2.4.68.

Reference: CVE-2026-56154 on NVD

← Back to Security News