CVE-2026-48913

Apache HTTP Server vulnerabilities

Beschreibung

Verwundbarkeit durch Verwendung nach Freigabe im Apache HTTP Server-Modul mod_http2, wenn Dateihandles bereits erschöpft sind. Dieses Problem betrifft den Apache HTTP Server: von Version 2.4.55 bis 2.4.67.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.3
Quelle: nvd-v3
39.9 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.5 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-07-20 19:03 UTC
CWE-416

Weakness-Klassen (CWE)

  • CWE-416Variant

    Use After Free

    The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Translated2026-07-23 07:10 UTC· nvd@nist.gov
    • Translation: Title: Apache HTTP Server, Description: Vulnerabilidad de Uso Después de Liberar en el módulo mod_http2 del Servidor HTTP Apache cuando los descriptores de archivo ya están agotados. Este problema afecta al Servidor HTTP Apache: desde 2.4.55 hasta 2.4.67.
  2. Initial Analysis2026-06-10 19:31 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* versions from (including) 2.4.55 up to (excluding) 2.4.68
    • Reference Type: CVE: http://www.openwall.com/lists/oss-security/2026/06/08/15 Types: Mailing List, Third Party Advisory
    • Reference Type: Apache Software Foundation: https://httpd.apache.org/security/vulnerabilities_24.html Types: Vendor Advisory
  3. CVE Modified2026-06-08 23:17 UTC· af854a3a-2127-422b-91ae-364da2661108
    • Reference: http://www.openwall.com/lists/oss-security/2026/06/08/15
  4. CVE Modified2026-06-08 19:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
  5. New CVE Received2026-06-08 16:16 UTC· security@apache.org
    • Description: Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.
    • CWE: CWE-416
    • Reference: https://httpd.apache.org/security/vulnerabilities_24.html

Betroffene Betriebssysteme

  • linux

    debian / debian_linux11.0

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • apache

    http_server2.4.0 – 2.4.68

  • bitnami

    apache2.4.0

  • bitnami

    apache2.4.17

  • bitnami

    apache2.4.55

  • bitnami

    apache

Quellen & Referenzen

Verknüpfte CVEs

Verknüpfte Empfehlungen

IDCVE-2026-48913
Apache HTTP Server vulnerabilities — CVE-2026-48913 | NEOSEC Intel