Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
ID: 991092ce-8877-53cb-8cc0-1f7e98f5b55d
STIX ID: report--991092ce-8877-53cb-8cc0-1f7e98f5b55d
Feed Name: The Hacker News
Threat Score
The Apache Software Foundation released fixes for CVE-2026-23918, a critical double-free in mod_http2 (affecting httpd 2.4.66) that enables trivial denial-of-service and a practical remote code execution path in environments using the APR mmap allocator; the advisory details the trigger (HTTP/2 HEADERS followed by RST_STREAM), PoC exploitation using mmap reuse and scoreboard memory, credited researchers, and recommends upgrading to 2.4.67.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
