CVE-2026-23918
HIGH 8.8EPSS 49.7%
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 49.73% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2026-05-04
- Updated
- 2026-07-15
Proof-of-concept exploits (9)
- striga-ai/CVE-2026-2391832★ · 2026-05-11
- xeloxa/CVE-2026-23918-Apache-H2-PoC23★ · 2026-05-06
- rhasan-com/CVE-2026-239188★ · 2026-05-06
- 12lie20/CVE-2026-23918-test4★ · 2026-05-05
- hackervlogofficial/CVE-2026-239181★ · 2026-05-06
- seguridadentrerios/CVE-2026-239180★ · 2026-05-06
- Bencodin/CVE-2026-23918-poc0★ · 2026-05-13
- CYFARE/CVE-2026-23918-Apache-HTTP-Server-DoubleFree-PoC0★ · 2026-05-06
- gagaltotal/CVE-2026-23918-Double-free-Apache-httpd-mod_http20★ · 2026-06-29