Double free in Apache HTTP Server - CVE-2026-23918
Published: May 4, 2026
Apache HTTP Server
Apache Foundation
Description
The vulnerability allows a remote attacker to cause a denial of service and possibly execute arbitrary code.
The vulnerability exists due to a double free in Apache HTTP Server HTTP/2 handling when processing an early reset. A remote attacker can trigger an early reset condition to cause a denial of service and possibly execute arbitrary code.
The issue is specific to the HTTP/2 protocol.