apache http-server CVE-2026-56153 is a vulnerability in Apache HTTP Server
Published on October 1, 2026

Apache HTTP Server: mod_charset_lite: Heap overflow in finish_partial_char
Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Vendor Advisory NVD

Timeline

reported

fixed in 2.4.x by r1938658 114 days later.

2.4.69 released

Weakness Type

What is a Memory Corruption Vulnerability?

The software writes data past the end, or before the beginning, of the intended buffer. Typically, this can result in corruption of data, a crash, or code execution. The software may modify an index or perform pointer arithmetic that references a memory location that is outside of the boundaries of the buffer. A subsequent write operation then produces undefined or unexpected results.

CVE-2026-56153 has been classified to as a Memory Corruption vulnerability or weakness.


Products Associated with CVE-2026-56153

Want to know whenever a new CVE is published for Apache HTTP Server? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache HTTP Server: