Apache HTTP Server 2.4.69 fixes 23 vulnerabilities, including memory-safety flaws in mod_http2 and mod_dav: update web servers
EditorialBy TrustList Editorial
Apache released HTTP Server 2.4.69 on 1 October 2026 with fixes for 23 vulnerabilities: five rated moderate by the project, such as a mod_http2 use-after-free and mod_dav overflows, and 18 low. National CERTs rate several higher. Update 2.4.x.
- Cybersecurity
- Vulnerability Management
- Patch Management
- Web Development
About Apache HTTP Server 2.4.69 fixes 23 vulnerabilities, including memory-safety flaws in mod_http2 and mod_dav: update web servers
Apache HTTP Server 2.4.69 fixes 23 vulnerabilities, including memory-safety flaws in mod_http2 and mod_dav: update web servers
2 October 2026 — The Apache Software Foundation released Apache HTTP Server 2.4.69 on 1 October 2026. The project's security page lists 23 vulnerabilities fixed in it: 5 rated moderate and 18 low by Apache. Italy's CSIRT and Spain's INCIBE-CERT issued alerts on 2 October; scoring the same flaws by CVSS, they rate several of them critical or high. No exploitation has been reported.
Not yet independently verified. The project and the national CERTs disagree on severity: Apache rates none above moderate, while the CERTs’ CVSS scores put several in the critical and high bands. We give Apache’s ratings and counts; the CERTs counted 20 flaws against the project’s 23. We will update this when it can be confirmed, and remove this note.
The moderate flaws
- CVE-2026-57941: use-after-free or wild write in mod_http2 through shared session re-entrancy.
- CVE-2026-42528: shared-lock overflow in mod_dav.
- CVE-2026-93546: namespace overflow in mod_dav_fs.
- CVE-2026-63292: stack overflow in mod_vhost_alias.
- CVE-2026-59685: out-of-bounds write in
ap_directory_walk()on case-insensitive filesystems.
Among the 18 low-rated flaws are a limited remote code execution for some internal redirects in CGI directories (CVE-2026-42356), response smuggling in mod_proxy_uwsgi, several mod_auth_digest replay and denial-of-service flaws, a session cookie not removed during internal redirects in mod_session, and fixes that re-address three 2024 flaws, including an SSRF with mod_headers.
Who should act
Apache httpd runs a large share of the world's websites, and it is also embedded in appliances, hosting control panels, application servers and vendor products, where it is updated only when the vendor ships a new build. Memory-safety flaws in modules such as mod_http2 and mod_dav are the kind researchers turn into working attacks after a release.
What to do
- Update every Apache 2.4.x server to 2.4.69, starting with internet-facing ones that use HTTP/2 or WebDAV.
- If you cannot update today, disable modules you do not use (mod_dav, mod_dav_fs, mod_vhost_alias, mod_proxy_uwsgi, mod_auth_digest) and review HTTP/2 exposure.
- Linux distributions backport fixes under their own version numbers: check your distribution's advisory rather than the version string.
- Ask appliance and software vendors whose products bundle Apache when they will ship 2.4.69.
Sources
Categories & features
- Cybersecurity
- Vulnerability Management
- Patch Management
- Web Development
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.