Summary
Double free in Apache HTTP Server's HTTP/2 handling can corrupt memory in the httpd process. It affects Apache HTTP Server 2.4.66 when HTTP/2 is enabled. A remote attacker can send crafted HTTP/2 traffic that hits the early-reset path and may lead to remote code execution without user interaction.
Why Planned Fix?
4/6Exploitation Details
Execute arbitrary code as the Apache worker user.
RCE (Remote Code Execution)Affected Software
| Product | Affected Versions |
|---|---|
| Apache HTTP Server | 2.4.66 |
Open-source web server and reverse proxy used to serve websites, applications, and HTTP APIs.
Affected ComponentHTTP/2 stream handling in mod_http2, especially the early reset cleanup path.
HTTP/2 stream handling in mod_http2, especially the early reset cleanup path.
Not available
Not available
Upgrade Apache HTTP Server to 2.4.67 or later; version 2.4.67 fixes CVE-2026-23918.
Upgrade Apache HTTP Server to 2.4.67 or later; version 2.4.67 fixes CVE-2026-23918.
Probability of exploitation in the next 30 days
Worse than 19% of all CVEs
No known threat actors
No detection rules available
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Affected Software (CPE) (1)
- •cpe:2.3:a:apache:http_server:2.4.66:*:*:*:*:*:*:*
Sources
| Source | Article |
|---|---|
| httpd.apache.org | Apache HTTP Server 2.4 vulnerabilities |
| nvd.nist.gov | CVE-2026-23918 Detail |
| httpd.apache.org | Apache Module mod_http2 |
| seclists.org | oss-sec: CVE-2026-23918 |
| ubuntu.com | CVE-2026-23918 |
| thehackernews.com | Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE |
Priority History
Initial analysis