CVE-2026-23918

Security update for apache2

Description

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Metrics

Severity
high
PoC (publicly reported)
8.8
Source: nvd-v3
98.8 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
49.7 %
Elevated — model estimates 10-50% exploitation likelihood.
Published
2026-08-27 14:44 UTC
CWE-415

Weakness classes (CWE)

  • CWE-415Variant

    Double Free

    The product calls free() twice on the same memory address.

    cwe.mitre.org →

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • apache

    http_server2.4.67

  • bitnami

    apache2.4.0

  • bitnami

    apache2.4.30

  • bitnami

    apache2.4.66

  • bitnami

    apache

References & sources

Linked CVEs

Linked advisories

IDCVE-2026-23918