Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Stanislaw Strzalkowski

Researcher fromisec.pl
#24719of 56,328
10Total CVSS
Vulnerabilities · 1
PT-2026-36811
10
2025-12-10
Apache · Apache Http Server · CVE-2026-23918
**Name of the Vulnerable Software and Affected Versions** Apache HTTP Server version 2.4.66 **Description** A double free error exists within the HTTP/2 protocol implementation. A double free occurs when the software attempts to release the same memory space twice, which can corrupt heap structures. This flaw allows a remote, unauthenticated attacker to execute arbitrary code or cause a denial of service by sending specially crafted HTTP/2 traffic. The issue is particularly critical for servers handling multiple tenants or user-driven content, as attackers can establish numerous connections and streams to trigger the flaw. Standard authentication methods, such as basic authentication or reverse proxy authentication, do not prevent the establishment of the malicious HTTP/2 connections required for exploitation. **Recommendations** Upgrade Apache HTTP Server to version 2.4.67 or later.