Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
| Vendor | Product | Versions |
|---|---|---|
| apache | http_server | 2.4.66 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| apache | http | cert_advisory | 90% |
| apple | macos | cert_advisory | 90% |
Added a detailed description of the vulnerability and new relevant tags.
Updated description with CVE-2026-23918, marked exploit as available, noted it is actively exploited, and indicated no patch version number provided.
Updated description with new technical details, marked the vulnerability as CRITICAL, and noted that it is actively exploited.
Initial creation