## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-ALT3KX-CVE-2026-23918
# CVE-2026-23918 Apache mod_http2 双重释放检测器

https://github.com/user-attachments/assets/d6c30e58-548c-4b6d-9ba3-baa667238a58
root@kitploit:~
python3 h2ghost.py -h
usage: h2ghost.py [-h] [--host HOST] [--port PORT] [--tls] [--no-tls] [--iterations ITERATIONS]
[--burst-n BURST_N] [--timeout TIMEOUT] [--crash-threshold CRASH_THRESHOLD]
[--crash-multiplier CRASH_MULTIPLIER] [--crash-min-delta CRASH_MIN_DELTA]
[--output OUTPUT] [--check-only] [--skip-check] [--verbose]
[TARGET]
Apache mod_http2 CVE-2026-23918 - double-free detector
positional arguments:
TARGET https://host:port http://host host:port host IP
options:
-h, --help show this help message and exit
--host HOST Target host (alt to positional)
--port PORT Target port (inferred from scheme/target if omitted)
--tls Force TLS/HTTPS (default: auto-detect)
--no-tls Force plain TCP / h2c
--iterations ITERATIONS
--burst-n BURST_N Triggers in check phase (default 10)
--timeout TIMEOUT Connection timeout s (default 2.5; use 5+ for internet)
--crash-threshold CRASH_THRESHOLD
Fallback absolute ms when no baseline (default 150)
--crash-multiplier CRASH_MULTIPLIER
reconnect/baseline ratio to flag as crash (default 1.3x)
--crash-min-delta CRASH_MIN_DELTA
min ms above baseline (AND ratio) to flag crash (default 80ms)
--output OUTPUT
--check-only
--skip-check
--verbose
Crash detection logic
---------------------
Trigger connection closing is NORMAL on both servers.
A crash requires: PING fails on a FRESH connection AND
reconnect > 150 ms (MPM restart delay).
Examples
--------
python3 h2ghost.py https://127.0.0.1:9443 --check-only
python3 h2ghost.py 127.0.0.1:7443 --check-only
python3 h2ghost.py 127.0.0.1:9443 --iterations 200
python3 h2ghost.py https://example.com --burst-n 20
# 漏洞摘要
# 技术细节
* **拒绝服务(DoS):** 使用以下方式即可轻松触发:
* `1 个连接`
* `2 个 HTTP/2 帧`
* **潜在 RCE 向量**
* APR mmap 分配器
* Debian / Docker 环境
* **修复**
* Apache httpd `2.4.67`
* mod_http2 `2.0.37`
# 致谢
## 漏洞发现
* Bartlomiej Dmitruk - Striga.ai
* Stanislaw Strzalkowski - ISEC.pl
## 检测器脚本
* Alex Hernandez 又名 _(@_alt3kx_)_
# 参考链接
* https://vulners.com/cve/CVE-2026-23918
* https://httpd.apache.org/security/vulnerabilities_24.html
* https://github.com/apache/httpd/blob/trunk/CHANGES
* https://bz.apache.org/bugzilla/show_bug.cgi?id=69899
# 免责声明
本项目严格仅供以下用途:
* 经授权的安全评估
* 防御性测试
* 教育研究
未经明确书面许可对系统进行未授权测试可能违反适用法律。
作者对滥用行为不承担任何责任。