CVE-2026-23918

CVE-2026-23918: Apache HTTP Server: http2: double free and possible RCE on early reset

Vendor Apache Software Foundation
Product Apache HTTP Server
Weakness CWE-415
Published May 4, 2026
Last update July 15, 2026

CVSS base score

What the vulnerability does

01Description

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Key dates

02Disclosure timeline

May 4, 2026 CVE published
July 15, 2026 Record updated