Apache HTTP Server Security Advisory: Critical RCE and Request Splitting Vulnerabilities in Version 2.4.68
CVE-2026-42356 & CVE-2026-42528 (CWE-444 (Inconsistent Interpretation of HTTP Requests) / CWE-120 (Buffer Overflow))
Severity: HIGH / CRITICAL (CVSS 8.8 / 7.5)
Status: Official Vendor Security Release Issued October 9, 2026
Affected Systems: Apache HTTP Server versions prior to 2.4.69
Fixed In: Apache HTTP Server 2.4.69
On October 9, 2026, the Apache Software Foundation released Apache HTTP Server version 2.4.69, addressing multiple high-severity security vulnerabilities. The most critical flaws—tracked as CVE-2026-42356 and CVE-2026-42528—affect reverse proxy configurations and HTTP/2 protocol translation modules, allowing remote threat actors to execute HTTP request smuggling, bypass access controls, or trigger remote code execution in vulnerable server environments.
Technical Breakdown of Disclosed Flaws
1. CVE-2026-42356: Reverse Proxy Request Smuggling & Header Normalization
When Apache HTTP Server is configured as a reverse proxy using mod_proxy_http, an inconsistency in how multi-line folded headers and chunked transfer encodings are normalized allows an attacker to smuggle hidden HTTP requests to downstream application servers. By submitting conflicting Transfer-Encoding and Content-Length headers with whitespace variations, the proxy processes the request boundaries differently than the backend application server, enabling cache poisoning and authentication bypass.
2. CVE-2026-42528: Memory Corruption in HTTP/2 Stream Multiplexing
The second vulnerability resides in mod_http2 during concurrent multiplexed stream termination. Under heavy stream load, an unexpected RST_STREAM frame transmitted while a large payload is being processed causes a race condition that results in a use-after-free condition in memory pools. This can be exploited to crash the worker process or execute arbitrary code under specific memory layouts.
Impacted Modules & Configuration Checks
Organizations should verify whether their Apache deployments utilize the affected modules:
# Check loaded Apache modules on Linux
apache2ctl -M | grep -E "(proxy_http|http2)"
# Or on RHEL / CentOS:
httpd -M | grep -E "(proxy_http|http2)"
If proxy_http_module or http2_module is enabled in conjunction with edge reverse proxying, the installation must be prioritized for patching.
Remediation Guidance
- Upgrade to Apache 2.4.69: Update package repositories and install the latest stable release. Linux distributions (Debian, Ubuntu, RHEL, Alpine) are releasing patched packages.
- Audit Reverse Proxy Logs: Search web logs for requests containing malformed or duplicate
Transfer-Encodingheaders.
Workaround for Request Smuggling: If patching cannot be completed immediately, ensure HttpProtocolOptions Strict is set in httpd.conf to enforce RFC-compliant header parsing:
HttpProtocolOptions Strict