PT-2026-36811 · Apache+4 · Apache Http Server+4

·

CVE-2026-23918

·

Published

2025-12-10

·

Updated

2026-08-27

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache HTTP Server version 2.4.66
Description A double free error exists within the HTTP/2 protocol implementation. A double free occurs when the software attempts to release the same memory space twice, which can corrupt heap structures. This flaw allows a remote, unauthenticated attacker to execute arbitrary code or cause a denial of service by sending specially crafted HTTP/2 traffic. The issue is particularly critical for servers handling multiple tenants or user-driven content, as attackers can establish numerous connections and streams to trigger the flaw. Standard authentication methods, such as basic authentication or reverse proxy authentication, do not prevent the establishment of the malicious HTTP/2 connections required for exploitation.
Recommendations Upgrade Apache HTTP Server to version 2.4.67 or later.

Exploit

Fix

DoS

RCE

NULL Pointer Dereference

Multiple Releases of Same Resource or Handle

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-86004
BDU:2026-06305
BDU:2026-06409
BIT-APACHE-2026-23918
CVE-2026-23918
OPENSUSE-SU-2026:10785-1
OPENSUSE-SU-2026:21115-1
RHSA-2026:13938
SUSE-SU-2026:2103-1
SUSE-SU-2026:2104-1
SUSE-SU-2026:22199-1
SUSE-SU-2026:22209-1
SUSE-SU-2026:2641-1
SUSE-SU-2026:2686-1
USN-8239-1

Affected Products

Apache Http Server
Linuxmint
Apple Macos
Red Os
Ubuntu