{
  "from_raw": "Eric Covener <covener@apache.org>",
  "from": "Eric Covener <co...@apache.org>",
  "gravatar": "ee9bd44fca004cd144fce0d972679406",
  "to": "an...@apache.org,\n de...@httpd.apache.org",
  "subject": "CVE-2026-56154: Apache HTTP Server: mod_rewrite use-after-free via %{LA-U:HTTP:...}",
  "message-id": "<44129c0a-f54c-afee-0c43-c5687a4d8b6f@apache.org>",
  "mid": "9z0c7z6kb5dm7t2h3fwdy4jd8d9xl6ng",
  "permalinks": [
    "9z0c7z6kb5dm7t2h3fwdy4jd8d9xl6ng",
    "r00ab0826e927b6db08fbe19eaec7f77a6bc8f7bf3d75db237bbe8cc2@<announce.apache.org>"
  ],
  "dbid": "589ee84bc9bce2dd4d3e3486ce0b3da917a09a6ee203b8740c95d3254e7d55af",
  "cc": "de...@httpd.apache.org",
  "epoch": 1790877931,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/10/01 18:05:31",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: low \n\nAffected versions:\n\n- Apache HTTP Server 2.4.0 through 2.4.68\n\nDescription:\n\nUse After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...})\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.\n\nCredit:\n\nNebula Security (@nebusecurity) (finder)\n\nReferences:\n\nhttps://httpd.apache.org/security/vulnerabilities_24.html\nhttps://httpd.apache.org/\nhttps://www.cve.org/CVERecord?id=CVE-2026-56154\n\nTimeline:\n\n2026-05-25: reported\n2026-10-01: fixed in 2.4.x by r1938660\n2026-10-01: 2.4.69 released\n\n",
  "body_short": "Severity: low \n\nAffected versions:\n\n- Apache HTTP Server 2.4.0 through 2.4.68\n\nDescription:\n\nUse After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...})\n\n\n\n",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 3172,
  "id": "9z0c7z6kb5dm7t2h3fwdy4jd8d9xl6ng"
}