High severity8.8NVD Advisory· Published May 4, 2026· Updated Jul 15, 2026
CVE-2026-23918
CVE-2026-23918
Description
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.
This issue affects Apache HTTP Server: 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
25cpe:2.3:a:apache:http_server:2.4.66:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apache:http_server:2.4.66:*:*:*:*:*:*:*
- (no CPE)range: <=2.4.66
- osv-coords23 versionspkg:bitnami/apachepkg:rpm/opensuse/apache2&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/apache2&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/apache2-devel&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/apache2-event&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/apache2-manual&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/apache2-prefork&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/apache2-utils&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/apache2-worker&distro=openSUSE%20Leap%2016.0pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0pkg:rpm/suse/apache2-devel&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/apache2-devel&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0pkg:rpm/suse/apache2-event&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/apache2-event&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0pkg:rpm/suse/apache2-manual&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/apache2-manual&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0pkg:rpm/suse/apache2-prefork&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/apache2-prefork&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0pkg:rpm/suse/apache2-utils&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/apache2-utils&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0pkg:rpm/suse/apache2-worker&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/apache2-worker&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0
>= 2.4.66, < 2.4.67+ 22 more
- (no CPE)range: >= 2.4.66, < 2.4.67
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.67-1.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
Patches
Vulnerability mechanics
References
6- www.openwall.com/lists/oss-security/2026/05/04/19nvdMailing ListThird Party Advisory
- httpd.apache.org/security/vulnerabilities_24.htmlnvdVendor Advisory
- access.redhat.com/errata/RHSA-2026:13938nvd
- access.redhat.com/security/cve/CVE-2026-23918nvd
- bugzilla.redhat.com/show_bug.cginvd
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23918.jsonnvd
News mentions
6- Apple Patches Everything (July 2026), (Wed, Jul 29th)SANS Internet Storm Center · Jul 29, 2026
- Debian 13.5 point release lands with security fixes, bug patchesHelp Net Security · May 17, 2026
- Patch Tuesday - May 2026Rapid7 Blog · May 13, 2026
- ⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and MoreThe Hacker News · May 11, 2026
- Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCEThe Hacker News · May 5, 2026
- Critical, High-Severity Vulnerabilities Patched in Apache MINA, HTTP ServerSecurityWeek · May 5, 2026