VORANT. Threat Intelligence Sign in Get the full feed

Apache HTTP Server HTTP/2 double-free flaw

high vulnerability

A double-free vulnerability in Apache HTTP Server's mod_http2 (CVE-2026-23918) can crash workers and, on some configs, enable remote code execution; PoC code exists.

CIS/MS-ISAC issued an advisory for CVE-2026-23918, a double-free vulnerability in Apache HTTP Server's mod_http2 module affecting versions prior to 2.4.67. The flaw is triggered by a crafted HTTP/2 stream sequence that causes the same stream to be cleaned up twice, leading to memory corruption. At minimum this allows an unauthenticated attacker to crash worker processes, causing denial of service with minimal effort.

Of greater concern, in certain configurations — notably those using APR with mmap, which is common on Debian systems and official Docker images — the memory corruption may be leveraged for remote code execution. Proof-of-concept code exists for both the denial-of-service and code-execution scenarios, though the advisory does not indicate confirmed in-the-wild exploitation. Given Apache HTTP Server's ubiquity as internet-facing infrastructure, organizations running affected versions should prioritize patching to 2.4.67 or later.

MS-ISAC recommends standard vulnerability management practices: prompt patching, automated patch management, vulnerability scanning, network segmentation to isolate internet-facing services, least-privilege configurations, and anti-exploitation controls. No specific threat actor or malware campaign has been linked to this vulnerability at this time.

Mentioned in this report

Vulnerabilities CVE-2026-23918poc

Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-apache-http-server-could-allow-for-remote-code-execution_2026-044

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free