Yaamlabs

Vulnerabilities

Apache httpd 2.4.69 fixes 20 flaws: what to patch first

Apache HTTP Server 2.4.69 fixes 20 CVEs in mod_http2, mod_rewrite, mod_ssl, WebDAV and more. Which configs are exposed, workarounds and checks.

The Apache HTTP Server Project released httpd 2.4.69 on October 1, 2026, fixing 20 vulnerabilities. Almost all of them affect every 2.4 release from 2.4.0 through 2.4.68, and one is specific to Windows. The bugs sit in modules: HTTP/2, mod_rewrite, mod_ssl, WebDAV, Digest authentication, the proxy family and mod_vhost_alias. Whether a given server is exposed depends on which of those modules it loads and how they are configured.

The severity depends on who you ask. Apache rates five of the flaws moderate and fifteen low. CISA's Authorized Data Publisher (ADP) enrichment in the National Vulnerability Database (NVD) scores the same twenty at 3 critical, 13 high, 3 medium and 1 low under CVSS 3.1, with three at 9.8. CISA's own enrichment marks exploitation as "none" for all twenty, and we found no report of attacks or public exploit code. That gives time to test and roll out the upgrade during this week's change window.

Why the two ratings disagree

CVSS scores the worst case for a flaw in isolation: a use-after-free in network-facing code with no login scores 9.8 because it could, in theory, give code execution. Apache's rating appears to weigh how unusual the triggering configuration is; in its advisory, the three 9.8 flaws include two it rates low, both tied to specific directives. Use the CVSS numbers to set the deadline in your patch policy, and Apache's notes to work out which of your servers actually run the vulnerable code.

How the main flaws work

CVE-2026-57941 in mod_http2

Apache rates it moderate; CISA's CVSS score is 9.8. mod_http2 handles HTTP/2 connections, keeping a temporary bucket brigade (a chain of data buffers) on each session. That buffer, the session's bbtmp field, is shared, and when the code re-enters itself while the buffer is still in use, memory is used after it has been freed, which Apache's title calls a possible "wild write". Any server with Protocols h2 http/1.1 (common behind TLS) runs this code.

CVE-2026-56154 in mod_rewrite

Also CVSS 9.8. mod_rewrite's lookahead variables, written as %{LA-U:HTTP:...}, make httpd run an internal subrequest to learn a value that is normally only known later in request processing. Using that lookahead on an HTTP header triggers a use-after-free. Only rule sets that use LA-U with HTTP: reach this code, and Apache rates it low.

CVE-2026-59797 in mod_ssl

The third 9.8, rated low by Apache. SSLRequire is a deprecated access-control directive that evaluates an expression, and it can be set in .htaccess files wherever AllowOverride AuthConfig is granted. The expression language includes file(), which reads a file from disk, and Apache's documentation marks it as restricted. Apache's advisory says only that SSLRequire let .htaccess files use these file functions, an improper privilege management flaw; read plainly, a user who can only edit their own directory gains a file-reading primitive running as the server. Shared hosting, where customers write their own .htaccess, carries the most exposure.

CVE-2026-63292 in mod_vhost_alias

Apache moderate, CVSS 7.5. mod_vhost_alias maps the Host header to a document root, for example VirtualDocumentRoot "/var/www/vhosts/%0". When the root uses a hostname format specifier and LimitRequestFieldSize has been raised above its default of 8190 bytes, a Host header over 8192 bytes overflows a stack buffer. Apache says this can crash the server or potentially run code. Servers with the default header limit do not hit it.

The rest

The other moderate flaws need more access or a specific platform. CVE-2026-93546 (CVSS 8.8) is an integer overflow in mod_dav_fs that lets a WebDAV user with write access crash workers and permanently corrupt a directory's property database with a PROPPATCH declaring many XML namespaces. CVE-2026-42528 crashes children via shared WebDAV locks. CVE-2026-59685 is an out-of-bounds write on Windows when 8.3 short file names grow on expansion.

The remaining low-rated fixes cover mod_heartmonitor, mod_session_cookie, mod_charset_lite, mod_proxy_html, mod_proxy_ftp, mod_xml2enc, mod_userdir and CGI handling. A few deserve a closer look if you use the feature. Digest authentication gets three fixes, including CVE-2026-73636 (CVSS 8.1), a replay of captured credentials when AuthDigestNonceLifetime 0 is set. CVE-2026-58415 lets anyone read WebDAV dead properties with a GET on the .DAV state directory. CVE-2026-63718 is response smuggling through mod_proxy_uwsgi when a backend sends Transfer-Encoding.

What attackers are doing

Nothing confirmed. Apache's advisory does not mention exploitation, CISA's enrichment for all twenty CVEs records exploitation as "none", and no CVE from this release appears in the CISA Known Exploited Vulnerabilities (KEV) catalog as of its October 4 update. Older Apache httpd flaws such as CVE-2021-41773 and CVE-2024-38475 are in that catalog, so a quiet first week is no guarantee for the next one.

What to do

1. Upgrade

Move to httpd 2.4.69, the only release that contains all twenty fixes. Most Linux servers run a distribution package, which keeps an older version number and backports fixes, so check your distribution's tracker for each CVE ID rather than reading httpd -v alone. Appliances and control panels that bundle Apache (hosting panels, NAS boxes, application servers) need their vendor's update. Confirm the running binary afterwards with httpd -v or apache2 -v on servers built from source.

2. If you cannot upgrade this week

First list what is loaded with apachectl -M (or httpd -M) and list virtual hosts with apachectl -S. Then:

  • HTTP/2: set Protocols http/1.1 in the server and virtual host config, or unload mod_http2. Clients fall back to HTTP/1.1.
  • mod_rewrite: grep -rn "LA-U:HTTP" /etc/httpd /etc/apache2 and replace those rules, for example with an <If> block or a check later in processing.
  • SSLRequire: grep for SSLRequire in every .htaccess under your document roots. Where users control .htaccess, drop AuthConfig from their AllowOverride until patched, and move your own rules to Require expr.
  • mod_vhost_alias: if VirtualDocumentRoot uses %0 or another %N specifier, set LimitRequestFieldSize back to 8190 or lower.
  • WebDAV: block GET requests for paths containing /.DAV/, and limit Dav On to authenticated users you trust.

3. Check for signs of trouble

Since nothing points to exploitation, this is about spotting probing. In the error log (/var/log/httpd/error_log or /var/log/apache2/error.log), look for AH00052: child pid ... exit signal Segmentation fault (11). A run of child crashes after October 1 on a server using HTTP/2, WebDAV or mod_vhost_alias is worth investigating. In the access log, look for requests with abnormally large Host headers or 400 responses to them, PROPPATCH requests from unexpected users, and GET requests for /.DAV/. On shared hosts, list .htaccess files changed recently with find /var/www -name .htaccess -newermt 2026-09-01 and read any that mention SSLRequire or file(.

4. After patching

If you find a crashed WebDAV directory, restore its property database from backup, since CVE-2026-93546 corrupts it permanently. Put back the HTTP/2 and header-size settings you changed, and plan to replace SSLRequire with Require expr for good, since the directive is deprecated.

Patch by module, not by version

On a typical server only a few of these twenty CVEs apply, and finding which ones is the slow part. Store the output of httpd -M and a grep of key directives (Protocols, VirtualDocumentRoot, Dav, AllowOverride, RewriteRule) with each server's inventory record, and the next Apache advisory can be matched against it in minutes.

Our safeguarding and hardening work reviews web server builds for unused modules and risky overrides, and our web penetration testing checks how HTTP/2, WebDAV and proxy configurations behave under hostile input. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.


Sources: Apache httpd 2.4 vulnerabilities, Apache httpd 2.4.69 release announcement, NVD: CVE-2026-57941, NVD: CVE-2026-56154, NVD: CVE-2026-59797, NVD: CVE-2026-63292, oss-security: CVE-2026-57941, SecurityOnline, Apache core documentation, Apache mod_ssl documentation.

Back to the blog, or read this post on the full site.