Apache Patched 20 Defects in HTTP Server. None of them rated it important

Apache HTTP Server 2.4.69 arrived on October 1 with fixes for 20 vulnerabilities. None are rated important or critical in the Apache advisory. Five are moderate, fifteen are low.

Know what this scale means before you decide how urgently to patch. Apache’s severity rating reflects its own assessment of realistic exploitation, and other databases have scored some of these considerably higher.

What is fixed

The versions affected vary by theme, so “2.4.0 to 2.4.68” is true for most but not all.

CVEModuleemissionAssessment
2026-63292mod_vhost_aliasFloor overflow, possible RCEmediocre
2026-93546mod_dav_fsInteger overflow, property DB corruptionmediocre
2026-57941mod_http2Use-no-free via shared bbtmpmediocre
2026-59685Core (Windows)Out-of-bounds writes in 8.3 waysmediocre
2026-42528mod_davCommon lock flood, child crashmediocre
2026-42356CGI handlingLimit RCE to internal redirectslow
2026-56154mod_rewriteUse-after-free via %{LA-U:HTTP:...}low
2026-59797mod_sslPrivilege management via SSLRequirelow
2026-63045mod_proxy_ftpPASV address validationlow
2026-63718mod_proxy_uwsgiAnswer smugglinglow
2026-79768is mod_userPath Equivalence Disclosurelow
2026-58415mod_dav_fsProperty database read accesslow

Plus eight more covers mod_heartmonitor, mod_session, mod_charset_lite, mod_proxy_html, mod_xml2enc and three separate mod_auth_digest issues.

Three flaws Apache calls low are 9.8 critical scored elsewhere

Three of these carry a criticality rating of 9.8 in the National Vulnerability Database, while Apache rates all three low:

CVEModuleweaknessApacheNVD page
2026-56154mod_rewriteCWE-416 Use After Freelow9.8 critical
2026-57941mod_http2CWE-416 Use After Freelow9.8 critical
2026-59797mod_sslCWE-269 Incorrect privilege managementlow9.8 critical

Attribution is important here, as it is loosely reported. NIST didn’t score any of them. All three NVD entries read “NVD rating not yet provided” in the NIST base score field. The 9.8 comes out CISA Authorized Data Publisher Programthe entries enriched NVD has not yet processed.

So the exact statement is that CISA scored them 9.8, NVD didn’t score them at all, and Apache scored them low.

One more detail can be seen on all three sides. Each has the identical vector string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Network reachable, low complexity, no privileges, no user interaction, high impact on confidentiality, integrity and availability.

The first to watch

  • mod_vhost_alias stack overflow. A remote client can cause denial of service or potentially execute code via a host header exceeding 8192 bytes. It needs VirtualDocumentRoot with a hostname format specifier and LimitRequestFieldSize increased above the default, so check if that describes your configuration.
  • CGI internal redirects. The target of some internal redirects from CGI programs can itself be treated as CGI and executed. It must already be sitting in a CGI-enabled directory without an extension mod_mime recognizes. Affects only 2.4.60 to 2.4.68.
  • mod_dav_fs integer overflow. An authenticated WebDAV client with write access can crash worker processes and persistently corrupt a directory’s properties database through PROPPATCH requests that declare many XML namespaces.
  • mod_auth_digest. Three separate issues in one release: forced reauthentication of unauthenticated clients, a capture-replay authentication bypass, and a use-free caused authentication state corruption. If you’re still using digest authentication, this is a question to think about.

Who they found

The acknowledgments say something about how server security research is done now.

CVE-2026-93546 credits Zhen Kong, Calif.io in collaboration with Anthropic, and AISLE in collaboration with Red Hat. The earlier release, 2.4.68, credits Quang Luong of Calif.IO in collaboration with the OpenAI Codex. Other finders include striga.ai, innora.ai, and depthfirst.

Several individual researchers appear again and again. Zhen Kong is credited on six of these twenty. Lucian Nitescu is credited on three.

Twenty CVEs in a single release of software this mature is unusual, and the pattern matches what OpenSSH described in its own release notes last week: more reports are coming, many are AI-assisted, and projects are shipping more often to keep.

Upgrade

Version 2.4.69 is the fix for all 20. There are no partial mitigations published for most of them.

If you’re running Apache behind a package manager, check if your distribution has backported the fixes instead of shipping 2.4.69 directly, as Debian, Ubuntu, RHEL, and others typically patch in place and keep the old version number.

Leave a Comment