CRITICAL
9.8 CVE-2026-56154 Published 1 Oct 2026
Apache HTTP Server mod_rewrite Use-After-Free Vulnerability
Worried this affects your website?
Apache HTTP Server contains a use-after-free vulnerability in its mod_rewrite module when using lookahead expressions such as %{LA-U:HTTP:...}.
This issue affects Apache HTTP Server versions from 2.4.0 through 2.4.68.
Reference: CVE-2026-56154 on NVD
← Back to Security News