Apache HTTP Server Security Advisory: Critical RCE and Request Splitting Vulnerabilities in Version 2.4.68

Apache HTTP Server Security Vulnerabilities Architecture
📌
Security Roundup Series: Week of October 9, 2026 • 4 min read deep dive
🚨
Vulnerability Intelligence: CVE ID: CVE-2026-42356 & CVE-2026-42528 (CWE-444 (Inconsistent Interpretation of HTTP Requests) / CWE-120 (Buffer Overflow)) Severity: HIGH / CRITICAL (CVSS 8.8 / 7.5) Status: Official Vendor Security Release Issued October 9, 2026 Affected Systems: Apache HTTP Server versions prior to 2.4.69 Fixed In: Apache HTTP Server 2.4.69

On October 9, 2026, the Apache Software Foundation released Apache HTTP Server version 2.4.69, addressing multiple high-severity security vulnerabilities. The most critical flaws—tracked as CVE-2026-42356 and CVE-2026-42528—affect reverse proxy configurations and HTTP/2 protocol translation modules, allowing remote threat actors to execute HTTP request smuggling, bypass access controls, or trigger remote code execution in vulnerable server environments.

Technical Breakdown of Disclosed Flaws

1. CVE-2026-42356: Reverse Proxy Request Smuggling & Header Normalization

When Apache HTTP Server is configured as a reverse proxy using mod_proxy_http, an inconsistency in how multi-line folded headers and chunked transfer encodings are normalized allows an attacker to smuggle hidden HTTP requests to downstream application servers. By submitting conflicting Transfer-Encoding and Content-Length headers with whitespace variations, the proxy processes the request boundaries differently than the backend application server, enabling cache poisoning and authentication bypass.

2. CVE-2026-42528: Memory Corruption in HTTP/2 Stream Multiplexing

The second vulnerability resides in mod_http2 during concurrent multiplexed stream termination. Under heavy stream load, an unexpected RST_STREAM frame transmitted while a large payload is being processed causes a race condition that results in a use-after-free condition in memory pools. This can be exploited to crash the worker process or execute arbitrary code under specific memory layouts.

Impacted Modules & Configuration Checks

Organizations should verify whether their Apache deployments utilize the affected modules:

# Check loaded Apache modules on Linux
apache2ctl -M | grep -E "(proxy_http|http2)"
# Or on RHEL / CentOS:
httpd -M | grep -E "(proxy_http|http2)"

If proxy_http_module or http2_module is enabled in conjunction with edge reverse proxying, the installation must be prioritized for patching.

Remediation Guidance

  1. Upgrade to Apache 2.4.69: Update package repositories and install the latest stable release. Linux distributions (Debian, Ubuntu, RHEL, Alpine) are releasing patched packages.
  2. Audit Reverse Proxy Logs: Search web logs for requests containing malformed or duplicate Transfer-Encoding headers.

Workaround for Request Smuggling: If patching cannot be completed immediately, ensure HttpProtocolOptions Strict is set in httpd.conf to enforce RFC-compliant header parsing:

HttpProtocolOptions Strict

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther