Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-23918

Опубликовано: 04 мая 2026
Источник: nvd
CVSS3: 8.8
EPSS Средний

Описание

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.

This issue affects Apache HTTP Server: 2.4.66.

Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:http_server:2.4.66:*:*:*:*:*:*:*

EPSS

Процентиль: 99%
0.49727
Средний

8.8 High

CVSS3

Дефекты

CWE-415
CWE-1341

Связанные уязвимости

CVSS3: 8.8
ubuntu
3 месяца назад

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVSS3: 8.8
redhat
3 месяца назад

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVSS3: 8.8
msrc
3 месяца назад

Apache HTTP Server: http2: double free and possible RCE on early reset

CVSS3: 8.8
debian
3 месяца назад

Double Free and possible RCE vulnerability in Apache HTTP Server with ...

CVSS3: 8.8
github
3 месяца назад

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

EPSS

Процентиль: 99%
0.49727
Средний

8.8 High

CVSS3

Дефекты

CWE-415
CWE-1341