Feed/CVE-2026-23918
CVE-2026-23918HIGHCVSS 8.8

CVE-2026-23918

Published May 4, 2026·Updated Jul 14, 2026

NVD Description

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Public Exploits & PoCs13 found

PoC: CVE-2026-23918

Apache httpd mod_http2 double-free, pre-auth RCE PoC

5

PoC: CVE-2026-23918

Apache HTTP/2 double-free vulnerability PoC (CVE-2026-23918)

3

PoC: CVE-2026-23918-Elite-Auditor

Elite reconnaissance script for auditing Apache's HTTP/2 stack against memory corruption (CVE-2026-23918). Features ALPN protocol forcing and monochrome dashboard intelligence. Built for Blue Teams and Security Researchers.

2

PoC: CVE-2026-23918-Apache-H2-PoC

Proof-of-Concept exploit for CVE-2026-23918 (Apache mod_http2 double-free). Features multi-mode DoS (Rapid-RST, Slow-Drip) and passive RCE/vulnerability detection for Apache 2.4.66.

1

[POC] MAL-2026-2307 — CVE-2026-23918-Double-free-Apache-httpd-mod_http2

Double-free in Apache httpd mod_http2 stream cleanup leading to pre-auth RCE

PoC: apache_audit_cve-2026-23918

Python toolkit to audit Apache HTTP Server against CVE-2026-23918 (HTTP/2 double-free RCE) and 4 related CVEs. Passive scanner with ALPN verification + read-only local auditor. No exploits.

PoC: Detections-CVE-2026-23918

Detection rules for CVE-2026-23918 Apache http2 RCE - Credit: stringa.ai, isec.pl

PoC: CVE-2026-23918

CVE-2026-23918 Apache mod_http2 Double-Free Detector

PoC: CVE-2026-23918-Apache-HTTP-Server-DoubleFree-PoC

CVE-2026-23918-Apache-HTTP-Server-DoubleFree-PoC

PoC: CVE-2026-23918

This is a proactive tool for security auditing. For your GitHub repository, you’ll want a description that highlights its safety (non-intrusive) and its specific utility for system administrators.

PoC: CVE-2026-23918-Passive-Audit

Passive HTTP metadata auditor for CVE-2026-23918 exposure triage

PoC: Apache-CVE-2026-23918-fix

Upgrade to Apache 2.4.67 to fix CVE-2026-23918 vulneribility

PoC: CVE-2026-23918-test

This repository contains a Proof of Concept (PoC) demonstrating the Double Free vulnerability (CVE-2026-23918) in Apache HTTP Server 2.4.66 `mod_http2`.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free