CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-23918

High · CVSS 8.8

Apache HTTP Server — Double Free RCE via HTTP/2 protocol

CVSS
8.8
nvd
EPSS
KEV
No
Class
other
CWE-415, CWE-1341

Description

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Search profile — drives PoC discovery

Symbols mod_http2h2_sessionh2_streamnghttp2double_freeHTTP/2ap_http2h2_connh2_task
Keywords CVE-2026-23918Apache HTTP ServerhttpdHTTP/2double freeRCECWE-415CWE-13412.4.662.4.67mod_http2Apache httpd PoCApache HTTP/2 double free exploit
Versions: 2.4.66

Ranked PoCs (15) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-06-30T18:30:14.000Z