CVE-2026-23918

medium Apache
Published: May 4, 2026 (9 days ago)
Last Modified: May 5, 2026
Vendor: Apache
Source: MITRE

Description

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CWE

CWE-415

Affected Products

Apache Software Foundation Apache HTTP Server

References