Apache HTTP Server mod_ldap Use-After-Free Vulnerability

Vulnerability

A use-after-free vulnerability has been identified in Apache HTTP Server versions 2.4.0 prior to 2.4.67, specifically within the mod_ldap module when used in per-directory configurations. This vulnerability can lead to memory corruption and potentially allow for arbitrary code execution.

Impact

Exploitation of this vulnerability can cause memory corruption, leading to a use-after-free condition. This type of vulnerability can often be exploited to execute arbitrary code under certain conditions.

Remediation

Users are advised to upgrade to Apache HTTP Server version 2.4.68, which addresses this vulnerability.

Added: Jun 8, 2026, 5:22 PM
Updated: Jun 8, 2026, 5:22 PM

Vulnerability Rating

Custom Algorithm
spread
9.4
impact
0.6
exploitability
7.6
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.