CVE-2026-23918
published 2026-05-04CVE-2026-23918: Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended…
PriorityP277high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EXPLOIT
EPSS
45.81%
98.7th percentile
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.
This issue affects Apache HTTP Server: 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
| apache | httpd | — | — |
| apache_software_foundation | apache_http_server | — | — |
| ubuntu | apache2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts by monitoring for HTTP/2 connections that send a HEADERS frame immediately followed by RST_STREAM with a non-zero error code on the same stream, before the stream is registered by the multiplexer. ↗
- →Flag single TCP connections delivering exactly two HTTP/2 frames (HEADERS + RST_STREAM) with no authentication, no special headers, and no specific URL targeting — this is the minimal DoS trigger pattern. ↗
- →For RCE path detection on Debian/Ubuntu or official httpd Docker images: monitor for mmap reuse patterns near freed h2_stream pool addresses, or unexpected writes to Apache scoreboard memory at a fixed address (stable across ASLR lifetime of the server process). ↗
- →Identify vulnerable servers via the Google dork targeting Apache/2.4.66 with HTTP/2 enabled in server banners. ↗
- →The exploit PoC uses the Python h2 library (ALPN negotiation for 'h2') over TLS; network sensors should flag high-frequency HTTP/2 connection establishments from a single source IP that each send minimal frames and immediately reset streams. ↗
- →MPM prefork is NOT affected; focus detection and patching efforts on servers running multi-threaded MPMs (worker, event) with mod_http2 loaded. ↗
- ·RCE exploitation is probabilistic (heap spray) and requires an information leak for system() address and scoreboard offsets; it is not a reliable one-shot exploit outside of lab conditions. ↗
- ·Only Apache HTTP Server version 2.4.66 is affected; Red Hat Enterprise Linux packages (RHEL 6–10) ship non-vulnerable mod_http2 builds and are listed as not affected, with the exception of Red Hat Hardened Images. ↗
- ·The double-free is in h2_mplx.c in the stream cleanup path; the specific code location is the spurge cleanup array receiving the same h2_stream pointer twice via h2_mplx_c1_client_rst -> m_stream_cleanup. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-05-06·CVSS 8.8
CVE-2026-28780 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
Bartlomiej Dmitruk and Stanislaw Strzalkowski discovered that Apache
HTTP Server incorrectly handled certain memory operations when using the
HTTP/2 protocol. A remote attacker could use this issue to cause Apache
HTTP Server to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-23918)
It was discovered that the Apache HTTP Server mod_rewrite module
incorrectly handled certain privileges. A local attacker could possibly use
this issue to obtain sensitive information. (CVE-2026-24072)
Andrew Lacambra, Elhanan Haenel, Tianshuo Han, and Tristan Madani
discovered that the Apache HTTP Server mod_proxy_ajp
Red Hat
Apache HTTP Server: Apache HTTP Server: Remote Code Execution via Double Free in HTTP/2 Protocol
vendor_redhat·2026-05-04·CVSS 8.8
CVE-2026-23918 [HIGH] CWE-1341 Apache HTTP Server: Apache HTTP Server: Remote Code Execution via Double Free in HTTP/2 Protocol
Apache HTTP Server: Apache HTTP Server: Remote Code Execution via Double Free in HTTP/2 Protocol
A flaw was found in Apache HTTP Server. This vulnerability, related to a double free error within the HTTP/2 protocol implementation, could potentially allow a remote attacker to execute arbitrary code. Successful exploitation could lead to a complete compromise of the affected system.
Statement: This issue marked as Important rather than Moderate because it involves a memory safety violation (double free) in the HTTP/2 request handling path, which is directly exposed to untrusted network input. A double free condition can corrupt the heap allocator’s internal metadata, enabling attackers to manipulate memory layout and potentially achieve arbitrary code execution (RCE) under favorable condit
GHSA
GHSA-p8fm-9c82-pw4g: Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol
ghsa_unreviewed·2026-05-04
CVE-2026-23918 [HIGH] CWE-415 GHSA-p8fm-9c82-pw4g: Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.
This issue affects Apache HTTP Server: 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
No detection rules found.
Bugzilla
Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
bugzilla·2026-05-06·CVSS 8.8
CVE-2026-23918 [HIGH] Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
No Builds in bodhi atm!
The vulnerability, tracked as CVE-2026-23918 (CVSS score: 8.8), has been described as a case of "double free and possible RCE" in the HTTP/2 protocol handling. This issue affects Apache HTTP Server 2.4.66 and has been addressed in version 2.4.67.
Reproducible: Always
Bugzilla
CVE-2026-23918 httpd: Apache HTTP Server: Remote Code Execution via Double Free in HTTP/2 Protocol [fedora-all]
bugzilla·2026-05-05·CVSS 8.8
CVE-2026-23918 [HIGH] CVE-2026-23918 httpd: Apache HTTP Server: Remote Code Execution via Double Free in HTTP/2 Protocol [fedora-all]
CVE-2026-23918 httpd: Apache HTTP Server: Remote Code Execution via Double Free in HTTP/2 Protocol [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-23918 Apache HTTP Server: Apache HTTP Server: Remote Code Execution via Double Free in HTTP/2 Protocol
bugzilla·2026-05-04·CVSS 8.8
CVE-2026-23918 [HIGH] CVE-2026-23918 Apache HTTP Server: Apache HTTP Server: Remote Code Execution via Double Free in HTTP/2 Protocol
CVE-2026-23918 Apache HTTP Server: Apache HTTP Server: Remote Code Execution via Double Free in HTTP/2 Protocol
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.
This issue affects Apache HTTP Server: 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Rapid7
Patch Tuesday - May 2026
blogs_rapid7·2026-05-13·CVSS 10.0
CVE-2026-41089 [CRITICAL] Patch Tuesday - May 2026
Microsoft is publishing 137 vulnerabilities on May 2026 Patch Tuesday . Microsoft is not aware of exploitation in the wild or public disclosure for any of these vulnerabilities. So far this month, Microsoft has provided patches to address 133 browser vulnerabilities, which are not included in the Patch Tuesday count above.
## Windows Netlogon: critical RCE
Anyone responsible for securing a domain controller should prioritize remediation of CVE-2026-41089 , which is a critical stack-based buffer overflow in Windows Netlogon with a CVSS v3 base score of 9.8. Exploitation leads to execution in the context of the Netlogon service, so that’s SYSTEM privileges on the domain controller. For most pentesters, that’s the point at which the customer report more or less writes itself. No privileges
Hackernews
⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More
blogs_hackernews·2026-05-11·CVSS 9.3
CVE-2026-6973 [CRITICAL] ⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More
Rough Monday.
Somebody poisoned a trusted download again, somebody else turned cloud servers into public housing, and a few crews are still getting into boxes with bugs that should’ve died years ago — the same old holes, same lazy access paths, same “how the hell is this still open” feeling. One report this week basically reads like a guy tripped over root access by accident and decided to stay there.
The weird part is how normal this all sounds now. Fake updates. Quiet backdoors. Remote tools are used like skeleton keys. Forum rats swapping st
Hackernews
Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
blogs_hackernews·2026-05-05·CVSS 8.8
CVE-2026-23918 [HIGH] Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
The Apache Software Foundation (ASF) has released security updates to address several security vulnerabilities in the HTTP Server, including a severe vulnerability that could potentially lead to remote code execution (RCE).
The vulnerability, tracked as CVE-2026-23918 (CVSS score: 8.8), has been described as a case of "double free and possible RCE" in the HTTP/2 protocol handling. This issue affects Apache HTTP Server 2.4.66 and has been addressed in version 2.4.67.
Striga.ai co-founder Bartlomiej Dmitruk and ISEC.pl researcher Stanislaw Strzalkowski
https://httpd.apache.org/security/vulnerabilities_24.htmlhttp://www.openwall.com/lists/oss-security/2026/05/04/19https://access.redhat.com/errata/RHSA-2026:13938https://access.redhat.com/security/cve/CVE-2026-23918https://bugzilla.redhat.com/show_bug.cgi?id=2465304https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23918.json
2026-05-04
Published