CVE-2026-23918
Apache Software Foundation Apache HTTP Server, Red Hat Hardened Images, Red Hat Enterprise Linux 10
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
- CVSS
- 8.8
- EPSS
- 49.7% 98.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.05