Sploitus

Exploit for CVE-2026-23918

kitploit · 2026-09-03

Exploit Code

MARKDOWN113 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-ALT3KX-CVE-2026-23918
# CVE-2026-23918 Apache mod_http2 双重释放检测器

![](https://assets.kitploit.com/production/public/readmes/42363/b2523d65392fc19a212202c5315a4ea2189706d6778f8e5fc65efe188e6b13e9.png)

https://github.com/user-attachments/assets/d6c30e58-548c-4b6d-9ba3-baa667238a58

root@kitploit:~
    
    
    python3 h2ghost.py -h
                                                        
    usage: h2ghost.py [-h] [--host HOST] [--port PORT] [--tls] [--no-tls] [--iterations ITERATIONS]
                      [--burst-n BURST_N] [--timeout TIMEOUT] [--crash-threshold CRASH_THRESHOLD]
                      [--crash-multiplier CRASH_MULTIPLIER] [--crash-min-delta CRASH_MIN_DELTA]
                      [--output OUTPUT] [--check-only] [--skip-check] [--verbose]
                      [TARGET]
    
    Apache mod_http2 CVE-2026-23918 - double-free detector
    
    positional arguments:
      TARGET                https://host:port http://host host:port host IP
    
    options:
      -h, --help            show this help message and exit
      --host HOST           Target host (alt to positional)
      --port PORT           Target port (inferred from scheme/target if omitted)
      --tls                 Force TLS/HTTPS (default: auto-detect)
      --no-tls              Force plain TCP / h2c
      --iterations ITERATIONS
      --burst-n BURST_N     Triggers in check phase (default 10)
      --timeout TIMEOUT     Connection timeout s (default 2.5; use 5+ for internet)
      --crash-threshold CRASH_THRESHOLD
                            Fallback absolute ms when no baseline (default 150)
      --crash-multiplier CRASH_MULTIPLIER
                            reconnect/baseline ratio to flag as crash (default 1.3x)
      --crash-min-delta CRASH_MIN_DELTA
                            min ms above baseline (AND ratio) to flag crash (default 80ms)
      --output OUTPUT
      --check-only
      --skip-check
      --verbose
    
    Crash detection logic
    ---------------------
      Trigger connection closing is NORMAL on both servers.
      A crash requires: PING fails on a FRESH connection AND
      reconnect > 150 ms (MPM restart delay).
    
    Examples
    --------
      python3 h2ghost.py https://127.0.0.1:9443 --check-only
      python3 h2ghost.py 127.0.0.1:7443 --check-only
      python3 h2ghost.py 127.0.0.1:9443 --iterations 200
      python3 h2ghost.py https://example.com --burst-n 20
    

# 漏洞摘要  
  
# 技术细节

  * **拒绝服务(DoS):** 使用以下方式即可轻松触发:

    * `1 个连接`
    * `2 个 HTTP/2 帧`
  * **潜在 RCE 向量**

    * APR mmap 分配器
    * Debian / Docker 环境
  * **修复**

    * Apache httpd `2.4.67`
    * mod_http2 `2.0.37`



# 致谢

## 漏洞发现

  * Bartlomiej Dmitruk - Striga.ai
  * Stanislaw Strzalkowski - ISEC.pl



## 检测器脚本

  * Alex Hernandez 又名 _(@_alt3kx_)_



# 参考链接

  * https://vulners.com/cve/CVE-2026-23918
  * https://httpd.apache.org/security/vulnerabilities_24.html
  * https://github.com/apache/httpd/blob/trunk/CHANGES
  * https://bz.apache.org/bugzilla/show_bug.cgi?id=69899



# 免责声明

本项目严格仅供以下用途:

  * 经授权的安全评估
  * 防御性测试
  * 教育研究



未经明确书面许可对系统进行未授权测试可能违反适用法律。

作者对滥用行为不承担任何责任。