The release in brief
On October 1, the Apache Software Foundation released Apache HTTP Server 2.4.69 with fixes for 20 security flaws. Five rate moderate, led by a mod_vhost_alias stack overflow that may allow code execution. The rest rate low, and no attacks have been reported.
Apache's release announcement calls 2.4.69 the latest general-availability release in the 2.4.x branch and recommends it over all earlier releases. It describes the update as a feature and bug-fix release. Some build details matter if you compile it yourself:
- It needs APR and APR-Util 1.5.x or later.
- Some features need version 1.6.x of both libraries.
- Apache says the APR libraries must be upgraded for all httpd features to work correctly.
The announcement also repeats that the 2.2.x branch is past end of life and gets no more security patches. If you still have a 2.2 server somewhere, these 20 fixes won't reach it.
Section summary: Upstream Apache fixes 20 CVEs in 2.4.69. Apache rates five moderate and fifteen low, and none have been reported as exploited.
The five moderate-rated flaws
These are the bugs Apache itself considers the most serious:
| CVE | Component | Issue | Affected versions |
|---|---|---|---|
| CVE-2026-63292 | mod_vhost_alias | Stack-based buffer overflow; DoS or possible code execution | Through 2.4.68 |
| CVE-2026-93546 | mod_dav_fs | Integer overflow; worker crashes and persistent property-database corruption | Through 2.4.68 |
| CVE-2026-57941 | mod_http2 | Use-after-free / wild write via shared session->bbtmp re-entrancy | 2.4.0–2.4.68 |
| CVE-2026-59685 | Core (Windows only) | Out-of-bounds write on 8.3 short-name paths that grow when expanded | 2.4.0–2.4.68 |
| CVE-2026-42528 | mod_dav | Memory calculation bug; WebDAV lock creators can crash child processes | Through 2.4.68 |
Each one only bites under certain conditions:
- mod_vhost_alias (CVE-2026-63292): Apache says a remote client can trigger the flaw using an oversized Host header when a server uses VirtualDocumentRoot with a hostname format specifier and has raised LimitRequestFieldSize above its default value. Apache's advisory puts the threshold at a Host header longer than 8,192 bytes. If you never raised that limit, you're likely not exposed. Some admins do raise it to fit large cookies or tokens, though.
- mod_dav_fs (CVE-2026-93546): An attacker needs to be an authenticated WebDAV user with write access. They can send PROPPATCH requests that declare many XML namespaces, which crashes workers and can permanently corrupt a directory's property database. "Persistent corruption" is a worse outcome than a crash that ends when the process restarts.
- mod_http2 (CVE-2026-57941): Memory-safety bugs in HTTP/2 processing are particularly relevant on internet-facing systems because requests are handled before application-level processing begins.
- Windows core (CVE-2026-59685): This one affects Windows only. The bug is in how httpd handles paths using legacy 8.3 short names (the
PROGRA~1style) that get longer when expanded. - mod_dav locks (CVE-2026-42528): The finder is Zhenpeng (Leo) Lin at depthfirst, and the report was received 2026-04-27.
Section summary: All five moderate bugs depend on specific modules or settings. Check whether you use WebDAV, HTTP/2, hostname-based virtual document roots, or a Windows host.
The fifteen low-rated flaws
"Low" here doesn't mean harmless. Several of these are worth a look depending on your setup:
- CVE-2026-42356 (CGI handling): A CGI program's internal redirect could cause Apache to run the destination file as another program. Still, the target file must already sit in a CGI-enabled folder. It also needs a file with no other extension that mod_mime recognises, and it only affects 2.4.60 through 2.4.68.
- CVE-2026-56154 (mod_rewrite): A use-after-free when rewrite rules use lookahead expressions like
%{LA-U:HTTP:...}. - CVE-2026-59797 (mod_ssl): Improper privilege management involving
SSLRequireand file-related expressions. - CVE-2026-63045 (mod_proxy_ftp): In forward-proxy setups, an untrusted FTP server can send a crafted PASV reply that makes the proxy open a data connection to an arbitrary third-party host.
- CVE-2026-63718 (mod_proxy_uwsgi): Response smuggling through a crafted uWSGI response using
Transfer-Encoding. It affects 2.4.30 through 2.4.68. - CVE-2026-79768 (mod_userdir): A
/./path-equivalence issue whenUserDiruses the absolute, non-wildcard form. - CVE-2026-58415 (mod_dav_fs): A remote client can read WebDAV dead properties for resources it can't author by requesting the
.DAVstate directory. - CVE-2026-46729 (mod_heartmonitor): Denial of service through the unicast listener.
- CVE-2026-47360 (mod_session_cookie): The session cookie can reach a backend after internal redirects.
- CVE-2026-56153 (mod_charset_lite): An out-of-bounds write.
- CVE-2026-56449 (mod_proxy_html): An out-of-bounds write triggered by crafted response bodies. It affects 2.4.68 only.
- CVE-2026-63686 (mod_xml2enc): A NULL pointer dereference that lets an untrusted backend crash the server when a charset conversion partly succeeds and then fails.
Three of the low-rated bugs are in mod_auth_digest:
- CVE-2026-48005: An unauthenticated remote client can cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck.
- CVE-2026-73636: A man-in-the-middle attacker can replay captured Digest authentication credentials in configurations where AuthDigestNonceLifetime is set to zero.
- CVE-2026-73637: A use-after-free that lets concurrent requests corrupt authentication state when
AuthDigestNcCheckis on orAuthDigestNonceLifetimeis 0.
If you still use Digest authentication, three bugs in one release is a good reason to plan a move to TLS with something stronger. That's general advice, not something Apache says in this advisory.
Section summary: The low-rated list covers proxying, rewrites, WebDAV disclosure, and Digest auth. Whether any of it matters to you depends almost entirely on which modules you load.
The severity dispute
How2Shout found that three of these CVEs carry a CVSS 3.1 score of 9.8 ("critical") on their National Vulnerability Database pages. The publication was right to be careful about who gave that score. NIST hadn't scored any of them, and the NVD base-score field read "NVD assessment not yet provided." The 9.8 came from CISA's Authorized Data Publisher (ADP) enrichment programme. All three pages showed the same vector, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That vector describes a bug reachable over the network, with low complexity, needing no privileges or user interaction, and with high impact on confidentiality, integrity and availability.
One correction to How2Shout's version. Its comparison table says Apache rated all three bugs low, but Apache's advisory lists the mod_http2 bug, CVE-2026-57941, as moderate. Apache did rate the mod_rewrite (CVE-2026-56154) and mod_ssl (CVE-2026-59797) bugs low. An independent check of the NVD page confirmed the CISA-ADP 9.8 for CVE-2026-57941 and CVE-2026-59797. The 9.8 for CVE-2026-56154 rests on How2Shout's report.
CISA isn't the only outside body that disagrees with Apache. According to Mallory's aggregation, Italy's CSIRT classifies three vulnerabilities as critical and 13 as high, while another advisory highlights five Moderate-severity issues.
Who's right? Probably both, for different reasons:
- CVSS enrichment often scores the worst-case shape of a bug class. A use-after-free reachable over the network gets the full 9.8 even when real exploitation needs uncommon settings.
- Apache's ratings take those settings into account. A bug that needs
LimitRequestFieldSizeraised, or a niche lookahead rewrite rule, gets marked down. Apache's advisory page also says its ratings may vary from platform to platform.
In practice, use Apache's labels to understand how likely exploitation is. Remember that many vulnerability scanners and compliance dashboards will show the 9.8, so auditors will probably ask you about these CVEs either way.
Section summary: Credit the 9.8 to CISA-ADP, not NIST. Apache rated the mod_http2 bug moderate, not low, and your scanners will probably flag these as critical.
Who found the bugs
The credits point to a trend. CVE-2026-93546 is credited to Zhen Kong, to Calif.io working with Anthropic, and to AISLE working with Red Hat. How2Shout notes that the previous release, 2.4.68, credited Quang Luong of Calif.IO working with OpenAI Codex. Other credited finders include striga.ai, innora.ai and depthfirst. Zhen Kong appears on six of the twenty CVEs and Lucian Nitescu on three. How2Shout ties this to recent comments from the OpenSSH project: more bug reports are arriving, many of them AI-assisted, and projects are shipping releases more often to keep up.
For admins, the takeaway is simple. AI-assisted bug hunting means more CVEs in mature software like httpd, so expect more frequent patch releases.
What to do on Windows and Linux
- Check your version. On Linux, run
httpd -v,apache2 -vorapachectl -v, depending on your distribution. On Windows, runhttpd.exe -vfrom the Apachebinfolder. - List loaded modules. Run
httpd -M(orapache2ctl -M). Look for mod_dav/mod_dav_fs, mod_http2, mod_vhost_alias, mod_auth_digest, mod_proxy_ftp, mod_proxy_uwsgi, mod_userdir, mod_proxy_html, mod_xml2enc, mod_charset_lite and mod_heartmonitor. Unloading modules you don't use cuts your exposure right away. - Review the risky settings. Check whether you use
VirtualDocumentRootwith a raisedLimitRequestFieldSize,AuthDigestNonceLifetime 0orAuthDigestNcCheck, CGI-enabled directories that receive internal redirects, and WebDAV write grants. - Upgrade. Upstream 2.4.69 fixes all 20 bugs, and How2Shout reports that most have no published partial workaround.
- Trust your distribution's advisory over the version number. Debian, Ubuntu, RHEL and others often backport fixes and keep the old version string. Tenable recommends 2.4.69-r0 or later for affected Alpine apache2 packages and separately flags CVE-2026-59797 as unpatched for Debian 12, 13, and 14, according to Mallory's summary. Check the current status for your own release.
Windows hosts need extra attention because of CVE-2026-59685. The Apache project publishes source code, not official Windows binaries (that's general industry knowledge), so Windows users usually get httpd from third-party builds or bundled stacks such as XAMPP-style packages. Check whether your provider has shipped a 2.4.69-based build before you mark the issue closed. Updating Windows itself won't patch it.
Section summary: Find out which modules you run, review the risky settings, upgrade to 2.4.69 or your vendor's patched package, and confirm your Windows build actually includes the fix.
Bottom line
Apache's "nothing important" verdict is reasonable for a default configuration. Few production servers run a default configuration, though. If you run WebDAV, HTTP/2, Digest auth, proxy modules or Apache on Windows, schedule this update for your next maintenance window rather than a far-off quarterly cycle.
References
- Apache Patched 20 Flaws in HTTP Server. It Rated None of Them Important - H2S Media H2S Media · 2026-10-07T07:03:02+00:00
- Apache HTTP Server 2.4.69 Fixes 20 Flaws, Including Code Execution Risks mallory.ai
- Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project httpd.apache.org