logo

Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE

ID: 991092ce-8877-53cb-8cc0-1f7e98f5b55d

STIX ID: report--991092ce-8877-53cb-8cc0-1f7e98f5b55d

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

The Apache Software Foundation released fixes for CVE-2026-23918, a critical double-free in mod_http2 (affecting httpd 2.4.66) that enables trivial denial-of-service and a practical remote code execution path in environments using the APR mmap allocator; the advisory details the trigger (HTTP/2 HEADERS followed by RST_STREAM), PoC exploitation using mmap reuse and scoreboard memory, credited researchers, and recommends upgrading to 2.4.67.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.