High severity8.8NVD Advisory· Published May 4, 2026· Updated May 4, 2026
CVE-2026-23918
CVE-2026-23918
Description
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.
This issue affects Apache HTTP Server: 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Affected products
1- cpe:2.3:a:apache:http_server:2.4.66:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.openwall.com/lists/oss-security/2026/05/04/19nvdMailing ListThird Party Advisory
- httpd.apache.org/security/vulnerabilities_24.htmlnvdVendor Advisory
News mentions
2- Patch Tuesday - May 2026Rapid7 Blog · May 13, 2026
- Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCEThe Hacker News · May 5, 2026