Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
internet-facing-service-vulnerabilitywidely-deployed-product-advisory

Apache HTTP Server fixes HTTP/2 double-free flaw with possible RCE

Updated 2mo agoFirst seen May 4, 202613 sources

The Apache Software Foundation released Apache HTTP Server 2.4.67 to fix five vulnerabilities, led by CVE-2026-23918, an important- to high-severity flaw in the HTTP/2 implementation. Apache said the bug is a double free triggered by an early reset that could lead to remote code execution, and that it affects version 2.4.66. The issue was reported in December 2025 and fixed shortly afterward, with public disclosure following on the oss-sec mailing list; Bartlomiej Dmitruk of striga.ai and Stanislaw Strzalkowski of isec.pl were credited with finding it.

The 2.4.67 release also patches CVE-2026-24072 in mod_rewrite, which can allow local .htaccess authors to read arbitrary files as the httpd user, along with lower-severity issues in mod_proxy_ajp, mod_md, and mod_dav_lock. Apache and downstream reporting urged organizations running 2.4.66 or earlier to upgrade immediately, while temporary mitigations for environments that cannot patch at once include disabling HTTP/2, removing mod_dav_lock, and reviewing .htaccess permissions.

Share:
Apache HTTP Server fixes HTTP/2 double-free flaw with possible RCE
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
May 6, 20262mo ago

Striga publishes technical analysis and exploitation details for CVE-2026-23918

On 2026-05-06, Striga published a write-up describing how an early HEADERS plus RST_STREAM sequence in mod_http2 could enqueue the same h2_stream pointer twice for cleanup, leading to a double free. The post also claimed a single connection with two HTTP/2 frames could crash a worker process and that lab testing achieved code execution with known system() and scoreboard addresses.

Striga says its Apache httpd scan surfaced CVE-2026-23918 - Bugflation
May 4, 20262mo ago

Apache publicly discloses CVE-2026-23918 on oss-sec

Apache publicly disclosed CVE-2026-23918 on the oss-sec mailing list on 2026-05-04. The advisory described the flaw as an important-severity HTTP/2 double free with possible remote code execution on early reset.

Apache releases HTTP Server 2.4.67 with CVE-2026-23918 patch

On 2026-05-04, the Apache Software Foundation released Apache HTTP Server 2.4.67, patching five vulnerabilities including CVE-2026-23918. Apache recommended upgrading from 2.4.66 to 2.4.67 to remediate the HTTP/2 double-free issue.

Dec 1, 20257mo ago

Apache fixes CVE-2026-23918 shortly after report

Apache fixed CVE-2026-23918 shortly after it was reported in December 2025. The issue affected Apache HTTP Server 2.4.66 and the remediation was prepared for a later public release.

Researchers report Apache HTTP Server HTTP/2 double-free flaw

Bartlomiej Dmitruk of striga.ai and Stanislaw Strzalkowski of isec.pl reported CVE-2026-23918 to Apache in December 2025. The flaw is a double free in Apache HTTP Server's HTTP/2 handling that could lead to remote code execution on early reset.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.