CVE-2026-23918
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
- Affected products
- Apache Http Server, Linuxmint, Apple Macos, Red Os, Ubuntu
- Apache Http Server
- = 2.4.66
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 49.7% (99th percentile)
- Weakness
- CWE-415, CWE-1341
- NVD status
- Modified
- Published
- 2026-05-04
CVE-2026-23918 at NVD
33 known exploits for CVE-2026-23918
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2026-23918-Apache-H2-PoC
CVE-2026-23918
CVE-2026-23918
CVE-2026-23918
CVE-2026-23918-Double-free-Apache-httpd-mod_http2
CVE-2026-23918-Passive-Audit
Apache-CVE-2026-23918-fix
CVE-2026-23918-Elite-Auditor
CVE-2026-23918-test
CVE-2026-23918
CVE-2026-23918-Apache-HTTP-Server-DoubleFree-PoC
CVE-2026-23918
CVE-2026-23918-poc
apache_audit_cve-2026-23918
Detections-CVE-2026-23918
cve-2026-poc-collection
cve-2026-poc-collection
π Apache 2.4.66 HTTP/2 mod_http2 Double-Free Denial of Service
π Apache HTTP Server 2.4.66 Denial of Service
Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service
cve-2026-poc-collection
Exploit for Double Free in Apache Http_Server
Exploit for Double Free in Apache Http_Server
Exploit for Double Free in Apache Http_Server
Exploit for Double Free in Apache Http_Server
Exploit for Double Free in Apache Http_Server
Exploit for Double Free in Apache Http_Server
Exploit for Double Free in Apache Http_Server
Exploit for Double Free in Apache Http_Server
Exploit for Double Free in Apache Http_Server
Exploit for Double Free in Apache Http_Server
Exploit for Double Free in Apache Http_Server
Exploit for Double Free in Apache Http_Server