CVE-2026-23918

HIGH LAB

Apache HTTP Server: http2: double free and possible RCE on early reset

Title source: cna
STIX 2.1

Description

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Exploits (9)

nomisec FAILED 3 stars
by rhasan-com · poc
https://github.com/rhasan-com/CVE-2026-23918
nomisec SCANNER 2 stars
by qassam-315 · poc
https://github.com/qassam-315/CVE-2026-23918-Elite-Auditor
nomisec WORKING POC 1 stars
by xeloxa · poc
https://github.com/xeloxa/CVE-2026-23918-Apache-H2-PoC
nomisec WORKING POC
by alt3kx · poc
https://github.com/alt3kx/CVE-2026-23918
nomisec WORKING POC
by CYFARE · poc
https://github.com/CYFARE/CVE-2026-23918-Apache-HTTP-Server-DoubleFree-PoC
nomisec SCANNER
by hackervlogofficial · poc
https://github.com/hackervlogofficial/CVE-2026-23918
nomisec FAILED
by seguridadentrerios · poc
https://github.com/seguridadentrerios/CVE-2026-23918
nomisec WRITEUP
by rshosting · poc
https://github.com/rshosting/Apache-CVE-2026-23918-fix
nomisec WORKING POC
by 12lie20 · poc
https://github.com/12lie20/CVE-2026-23918-test

References (2)

Core 2
Core References

Scores

CVSS v3 8.8
EPSS 0.0006
EPSS Percentile 18.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-415
Status published
Products (2)
apache/http_server 2.4.66
Apache Software Foundation/Apache HTTP Server 2.4.66
Published May 04, 2026
Tracked Since May 04, 2026