USN-8898-1: Apache HTTP Server vulnerabilities

Publication date

7 October 2026

Overview

Several security issues were fixed in Apache HTTP Server.


Packages

Details

It was discovered that Apache HTTP Server's mod_rewrite module incorrectly
handled memory when performing certain variable lookups. A remote attacker
could possibly use this issue to cause a denial of service or execute
arbitrary code. (CVE-2026-56154)

Lucian Nitescu, Simon Kappel, and Gianluca Danesin discovered that Apache
HTTP Server's mod_http2 module incorrectly handled memory when processing
certain HTTP/2 connections. A remote attacker could possibly use this issue
to cause a denial of service or execute arbitrary code. This issue only
affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04
LTS, and Ubuntu 26.04 LTS. (CVE-2026-57941)

Juthawong Naisanguansee, Charles Vosburgh, Mike Read, and Ryoma Nishioka
discovered that Apache HTTP Server's mod_ssl module incorrectly handled
certain expressions. An attacker could possibly...

It was discovered that Apache HTTP Server's mod_rewrite module incorrectly
handled memory when performing certain variable lookups. A remote attacker
could possibly use this issue to cause a denial of service or execute
arbitrary code. (CVE-2026-56154)

Lucian Nitescu, Simon Kappel, and Gianluca Danesin discovered that Apache
HTTP Server's mod_http2 module incorrectly handled memory when processing
certain HTTP/2 connections. A remote attacker could possibly use this issue
to cause a denial of service or execute arbitrary code. This issue only
affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04
LTS, and Ubuntu 26.04 LTS. (CVE-2026-57941)

Juthawong Naisanguansee, Charles Vosburgh, Mike Read, and Ryoma Nishioka
discovered that Apache HTTP Server's mod_ssl module incorrectly handled
certain expressions. An attacker could possibly use this issue to bypass
intended access restrictions. (CVE-2026-59797)


Update instructions

After a standard system update you need to restart apache2 to make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
26.04 LTS resolute apache2 –  2.4.66-2ubuntu2.5
apache2-bin –  2.4.66-2ubuntu2.5
apache2-dev –  2.4.66-2ubuntu2.5
apache2-ssl-dev –  2.4.66-2ubuntu2.5
apache2-suexec-custom –  2.4.66-2ubuntu2.5
apache2-suexec-pristine –  2.4.66-2ubuntu2.5
apache2-utils –  2.4.66-2ubuntu2.5
24.04 LTS noble apache2 –  2.4.58-1ubuntu8.16
apache2-bin –  2.4.58-1ubuntu8.16
apache2-dev –  2.4.58-1ubuntu8.16
apache2-ssl-dev –  2.4.58-1ubuntu8.16
apache2-suexec-custom –  2.4.58-1ubuntu8.16
apache2-suexec-pristine –  2.4.58-1ubuntu8.16
apache2-utils –  2.4.58-1ubuntu8.16
libapache2-mod-md –  2.4.58-1ubuntu8.16
libapache2-mod-proxy-uwsgi –  2.4.58-1ubuntu8.16
22.04 LTS jammy apache2 –  2.4.52-1ubuntu4.24
apache2-bin –  2.4.52-1ubuntu4.24
apache2-dev –  2.4.52-1ubuntu4.24
apache2-ssl-dev –  2.4.52-1ubuntu4.24
apache2-suexec-custom –  2.4.52-1ubuntu4.24
apache2-suexec-pristine –  2.4.52-1ubuntu4.24
apache2-utils –  2.4.52-1ubuntu4.24
libapache2-mod-md –  2.4.52-1ubuntu4.24
libapache2-mod-proxy-uwsgi –  2.4.52-1ubuntu4.24
20.04 LTS focal apache2 –  2.4.41-4ubuntu3.23+esm8  
apache2-bin –  2.4.41-4ubuntu3.23+esm8  
apache2-dev –  2.4.41-4ubuntu3.23+esm8  
apache2-ssl-dev –  2.4.41-4ubuntu3.23+esm8  
apache2-suexec-custom –  2.4.41-4ubuntu3.23+esm8  
apache2-suexec-pristine –  2.4.41-4ubuntu3.23+esm8  
apache2-utils –  2.4.41-4ubuntu3.23+esm8  
libapache2-mod-md –  2.4.41-4ubuntu3.23+esm8  
libapache2-mod-proxy-uwsgi –  2.4.41-4ubuntu3.23+esm8  
18.04 LTS bionic apache2 –  2.4.29-1ubuntu4.27+esm12  
apache2-bin –  2.4.29-1ubuntu4.27+esm12  
apache2-dev –  2.4.29-1ubuntu4.27+esm12  
apache2-ssl-dev –  2.4.29-1ubuntu4.27+esm12  
apache2-suexec-custom –  2.4.29-1ubuntu4.27+esm12  
apache2-suexec-pristine –  2.4.29-1ubuntu4.27+esm12  
apache2-utils –  2.4.29-1ubuntu4.27+esm12  
16.04 LTS xenial apache2 –  2.4.18-2ubuntu3.17+esm21  
apache2-bin –  2.4.18-2ubuntu3.17+esm21  
apache2-dev –  2.4.18-2ubuntu3.17+esm21  
apache2-suexec-custom –  2.4.18-2ubuntu3.17+esm21  
apache2-suexec-pristine –  2.4.18-2ubuntu3.17+esm21  
apache2-utils –  2.4.18-2ubuntu3.17+esm21  
14.04 LTS trusty apache2 –  2.4.7-1ubuntu4.22+esm16  
apache2-bin –  2.4.7-1ubuntu4.22+esm16  
apache2-dev –  2.4.7-1ubuntu4.22+esm16  
apache2-mpm-event –  2.4.7-1ubuntu4.22+esm16  
apache2-mpm-itk –  2.4.7-1ubuntu4.22+esm16  
apache2-mpm-prefork –  2.4.7-1ubuntu4.22+esm16  
apache2-mpm-worker –  2.4.7-1ubuntu4.22+esm16  
apache2-suexec –  2.4.7-1ubuntu4.22+esm16  
apache2-suexec-custom –  2.4.7-1ubuntu4.22+esm16  
apache2-suexec-pristine –  2.4.7-1ubuntu4.22+esm16  
apache2-utils –  2.4.7-1ubuntu4.22+esm16  
apache2.2-bin –  2.4.7-1ubuntu4.22+esm16  
libapache2-mod-macro –  1:2.4.7-1ubuntu4.22+esm16  
libapache2-mod-proxy-html –  1:2.4.7-1ubuntu4.22+esm16  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›