logo

Apache fixes critical HTTP/2 double-free flaw CVE-2026-23918 enabling RCE

ID: 716e3255-033d-5159-9a07-daedfbab8300

STIX ID: report--716e3255-033d-5159-9a07-daedfbab8300

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Pierluigi Paganini

...
...

Apache HTTP Server 2.4.66 contains a critical HTTP/2 double-free vulnerability (CVE-2026-23918, CVSS 8.8) in mod_http2 that can lead to memory corruption and denial-of-service and, in some setups (notably those using APR with mmap), remote code execution; the issue is fixed in 2.4.67 and a proof-of-concept exists—apply updates promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.