Apache HTTP Server mod_http2 Use-After-Free Vulnerability Exhausting File Handles

Vulnerability

A use-after-free vulnerability has been identified in the Apache HTTP Server module mod_http2. This vulnerability occurs when file handles are exhausted, leading to memory corruption. It affects Apache HTTP Server versions 2.4.55 prior to 2.4.67.

Impact

Exploitation of this vulnerability can lead to memory corruption, causing unpredictable behavior in the server process.

Remediation

Users are advised to upgrade to Apache HTTP Server version 2.4.68, which addresses this vulnerability.

Added: Jun 8, 2026, 4:28 PM
Updated: Jun 8, 2026, 4:28 PM

Vulnerability Rating

Custom Algorithm
spread
9.4
impact
1.3
exploitability
7.2
remediation
7.7
relevance
9.4
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.