CVE-2026-48913

CVE-2026-48913: Apache HTTP Server: mod_http2 memory corruption when file handles exhausted

Vendor Apache Software Foundation
Product Apache HTTP Server
Weakness CWE-416
Published June 8, 2026
Last update June 8, 2026

CVSS base score

What the vulnerability does

Description

Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.

Key dates

Disclosure timeline

June 8, 2026 CVE published
June 8, 2026 Record updated