CVE-2026-23918
Apache HTTP Server: http2: double free and possible RCE on early reset
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.
This issue affects Apache HTTP Server: 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Apache Software Foundation · Apache HTTP Serverpublic PoCs found — 7
githubgithub.com/striga-ai/CVE-2026-23918★ 29githubgithub.com/alt3kx/CVE-2026-23918★ 1githubgithub.com/aa022/CVE-2026-23918-Passive-Audit★ 0githubgithub.com/insomnisec/Detections-CVE-2026-23918★ 0githubgithub.com/Bencodin/CVE-2026-23918-poc★ 0githubgithub.com/sibersan/apache_audit_cve-2026-23918★ 0exploitdbwww.exploit-db.com/exploits/52577unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →