Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-23918

Опубликовано: 04 мая 2026
Источник: redhat
CVSS3: 8.8
EPSS Средний

Описание

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

A flaw was found in Apache HTTP Server. This vulnerability, related to a double free error within the HTTP/2 protocol implementation, could potentially allow a remote attacker to execute arbitrary code. Successful exploitation could lead to a complete compromise of the affected system.

Отчет

This issue marked as Important rather than Moderate because it involves a memory safety violation (double free) in the HTTP/2 request handling path, which is directly exposed to untrusted network input. A double free condition can corrupt the heap allocator’s internal metadata, enabling attackers to manipulate memory layout and potentially achieve arbitrary code execution (RCE) under favorable conditions. In this case, the flaw is triggered during an early stream reset in HTTP/2, meaning it can be exercised pre-authentication by a remote client without requiring complex application-level interaction. Given that Apache HTTP Server is widely deployed in internet-facing environments, even a low-probability RCE path significantly elevates risk.

Меры по смягчению последствий

To mitigate this issue, disable the mod_http2 module in your Apache HTTP Server configuration. This can be achieved by commenting out or removing the LoadModule http2_module modules/mod_http2.so line in the Apache configuration file (e.g., /etc/httpd/conf.modules.d/00-base.conf or a similar configuration file). After modifying the configuration, restart the httpd service for the changes to take effect. This action will impact services relying on HTTP/2 functionality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10httpdNot affected
Red Hat Enterprise Linux 10mod_http2Not affected
Red Hat Enterprise Linux 6httpdNot affected
Red Hat Enterprise Linux 7httpdNot affected
Red Hat Enterprise Linux 8httpd:2.4/httpdNot affected
Red Hat Enterprise Linux 8httpd:2.4/mod_http2Not affected
Red Hat Enterprise Linux 9httpdNot affected
Red Hat Enterprise Linux 9mod_http2Not affected
Red Hat JBoss Core Servicesmod_http2Not affected
Red Hat Hardened Imageshttpd-main-2.4.67-0.1.hum1FixedRHSA-2026:1393806.05.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1341
https://bugzilla.redhat.com/show_bug.cgi?id=2465304Apache HTTP Server: Apache HTTP Server: Remote Code Execution via Double Free in HTTP/2 Protocol

EPSS

Процентиль: 99%
0.49727
Средний

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
3 месяца назад

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVSS3: 8.8
nvd
3 месяца назад

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVSS3: 8.8
msrc
3 месяца назад

Apache HTTP Server: http2: double free and possible RCE on early reset

CVSS3: 8.8
debian
3 месяца назад

Double Free and possible RCE vulnerability in Apache HTTP Server with ...

CVSS3: 8.8
github
3 месяца назад

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

EPSS

Процентиль: 99%
0.49727
Средний

8.8 High

CVSS3