Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-23918

Опубликовано: 04 мая 2026
Источник: debian

Описание

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apache2fixed2.4.66-5package
apache2fixed2.4.66-1~deb13u2trixiepackage
apache2fixed2.4.67-1~deb12u2bookwormpackage
apache2not-affectedbullseyepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2026/05/04/19

  • https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-23918

  • https://github.com/apache/httpd/commit/e41e84e08e6186460e77a8357b5d5c571d33bd76 (2.4.67-rc1-candidate)

  • https://eissing.org/icing/posts/responsible-disclosure/

Связанные уязвимости

CVSS3: 8.8
ubuntu
3 месяца назад

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVSS3: 8.8
redhat
3 месяца назад

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVSS3: 8.8
nvd
3 месяца назад

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVSS3: 8.8
msrc
3 месяца назад

Apache HTTP Server: http2: double free and possible RCE on early reset

CVSS3: 8.8
github
3 месяца назад

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.