OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-56154

CRITICAL · CVSS 9.8 EPSS 0.42%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A use-after-free vulnerability exists in the mod_rewrite module of Apache HTTP Server versions 2.4.0 to 2.4.68 when utilizing lookahead directives. This flaw could potentially allow an attacker to execute arbitrary code, leading to unauthorized access or denial of service. Organizations running affected versions of Apache HTTP Server should prioritize patching this vulnerability to mitigate the associated risks.

CVE
CVE-2026-56154
Severity
CRITICAL
CVSS
9.8
EPSS
0.42%
Apache

Original NVD Description

Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Related CVEs

Other vulnerabilities affecting the same vendor(s)