Sceawere
Vulnerability Detail
CVE-2026-57941UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Use-After-Free in Apache mod_http2
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 1d ago
- Vendor
- Apache Software Foundation
- Product
- Apache HTTP Server
- Attack Type
- CWE-416 Use After Free
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-10-01T17:17:27.457Z",
"pubdate": "2026-10-01T17:17:27.457Z",
"executiveSummary": "A Use-After-Free (UAF) vulnerability exists in the Apache HTTP Server's mod_http2 module, specifically involving re-entrancy issues with the shared session->bbtmp bucket brigade buffer.\nThe vulnerability affects Apache HTTP Server versions 2.4.0 through 2.4.68.\nThis flaw allows a remote, unauthenticated attacker to trigger memory corruption by exploiting specific re-entrancy conditions during HTTP/2 request processing.\nSuccessful exploitation could lead to arbitrary code execution, denial-of-service (process crash), or information disclosure, depending on the attacker's ability to manipulate memory state.\nThe risk is high due to the core nature of the affected module and the potential for remote exploitation without prior authentication.",
"technicalDetails": "The vulnerability resides within the mod_http2 module, which is responsible for handling the HTTP/2 protocol in the Apache HTTP Server. The root cause is a Use-After-Free condition triggered by improper handling of the shared 'session->bbtmp' structure during re-entrant calls.\nIn the context of the Apache HTTP/2 implementation, 'bbtmp' serves as a temporary bucket brigade used during request/response stream processing. A re-entrancy vulnerability occurs when an execution flow is interrupted and resumed in such a way that the 'bbtmp' buffer is freed while a dangling pointer remains active in a different stage of the request processing lifecycle.\nThe attack flow initiates when an attacker sends specially crafted HTTP/2 frames that induce the server to trigger a nested or recursive call sequence within the session management logic. During this sequence, a specific codepath deallocates the memory associated with 'session->bbtmp' while subsequent logic attempts to access or append data to this same memory address. Because the pointer to 'session->bbtmp' is not properly invalidated or synchronized across the re-entrant call stack, the application performs operations on freed memory.\nExploitation requires the attacker to manipulate the heap layout to gain control over the freed object. By spraying the heap or triggering concurrent requests, an attacker may be able to replace the freed 'bbtmp' memory with controlled content. When the server subsequently references the dangling pointer, it processes the attacker-supplied data as if it were a valid bucket brigade structure, leading to potential control flow hijacking or arbitrary memory read/write primitives.\nThe vulnerability is accessible over the network without authentication, as it involves the core protocol handling logic. Given the asynchronous and multi-threaded nature of the Apache HTTP Server, timing the re-entrancy condition can be achieved by flooding the server with specific HTTP/2 frame sequences designed to induce race conditions or forced re-entry into the vulnerable code sections.\nThe impact includes potential memory corruption that can lead to remote code execution (RCE) if the attacker successfully overwrites function pointers or internal data structures, or server instability resulting in a crash and subsequent Denial of Service."
}