CVE-2026-56154
CVE-2026-56154
9.8
CriticalPublished:
Last updated:
Source:security@apache.org
Analyzed
Weakness (CWE)
CVSS Vector
v3.1- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Description
Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
References
security@apache.org
https://httpd.apache.org/security/vulnerabilities_24.htmlaf854a3a-2127-422b-91ae-364da2661108
http://www.openwall.com/lists/oss-security/2026/10/01/17