CVE-2026-57941

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 2 mentions (2026-10-01); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-10-01: 2Mentions · 2026-10-02: 210-0110-02
Referenced assets3 URLs
Full discourse4 posts
  • Kazuki Omo@omokazuki

    Apache HTTP Serverの脆弱性(Moderate: CVE-2026-42528, CVE-2026-57941, CVE-2026-59685, CVE-2026-63292, CVE-2026-93546, Low: 複数)と2.4.69リリース #sios_tech #security #vulnerability #セキュリティ #脆弱性 #apache https://security.sios.jp/vulnerability/apache-security-vulnerability-20261002/

    00011105
    374 followersView on X
  • Rıdvan Yağlı@ridvanyagli

    🔴 Apache HTTP Server 2.4.69 yayınlandı. Güncelleme, 2.4.68 ve öncesini etkileyen 20 güvenlik açığını gideriyor. Öne çıkan önemli açıklar: • CVE-2026-63292: mod_vhost_alias — DoS ve koşullu kod çalıştırma • CVE-2026-42356: CGI handler — sınırlı kod çalıştırma • CVE-2026-57941: mod_http2 — UAF / bellek yazma • CVE-2026-93546: mod_dav_fs — crash ve veritabanı bozulması Açıkların çoğu Moderate/Low seviyede ve sömürülebilirlik yapılandırmaya bağlı. Apache 2.4.69'a güncellemeyi düşünün. https://www.apachelounge.com/changelog-2.4.html

    00010152
    2.4K followersView on X
  • SecAlerts@SecAlertsCo

    🪶 Apache HTTP Server CVE-2026-57941: critical 9.8 use-after-free in mod_http2 via session->bbtmp re-entrancy. No auth needed, full C/I/A impact. Affects 2.4.0-2.4.68. Patch now. #cybersecurity #ciso #apache #vulnerabilities https://secalerts.co/vulnerability/CVE-2026-57941?utm_campaign=x https://t.co/BXagiSNGoT

    0000047
    894 followersView on X
  • VulDB 🛡@vuldb

    There is a new vulnerability with elevated criticality in Apache HTTP Server (CVE-2026-57941) vuldb.​com/vuln/412726

    00000127
    2.3K followersView on X

Explore more