Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
internet-facing-service-vulnerabilitywidely-deployed-product-advisoryproof-of-concept-releaserapid-weaponization

Apache HTTP Server mod_http2 Double-Free Exposes Pre-Auth RCE and DoS Risk

Updated 12d agoFirst seen May 25, 20265 sources

Apache HTTP Server disclosed CVE-2026-23918, a high-severity double-free flaw in mod_http2 affecting version 2.4.66, with researchers showing it can be triggered remotely over a single TCP connection by sending crafted HTTP/2 frames on the same stream. The bug stems from the same h2_stream object being queued twice for cleanup, causing a second apr_pool_destroy on freed memory; on multi-threaded MPM deployments such as event and worker, this can reliably crash worker processes without authentication, while prefork is not affected. Public reporting said denial-of-service is the most practical near-term outcome, but under specific conditions the memory corruption can be developed into pre-authenticated remote code execution.

Apache fixed the issue in version 2.4.67 by preventing duplicate cleanup entries and urged administrators to upgrade immediately. Guidance published alongside the disclosure recommended temporarily disabling HTTP/2 where patching is delayed, using rate limiting or a WAF to reduce opportunistic abuse, and reviewing exposure from related modules after the same release also patched flaws in mod_rewrite, mod_proxy_ajp, mod_md, and mod_dav_lock. At the time of publication, sources said there was no confirmed in-the-wild exploitation, but warned that Apache HTTP Server's broad deployment and common mod_http2 enablement make internet-facing systems attractive targets.

Share:
Apache HTTP Server mod_http2 Double-Free Exposes Pre-Auth RCE and DoS Risk
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Jun 8, 202615d ago

Apache releases HTTP Server 2.4.68

On 2026-06-08, the Apache Software Foundation announced the general availability of Apache HTTP Server 2.4.68 as a security, feature, and bug fix update for the 2.4.x branch. The project recommended upgrading from all previous releases and noted that the 2.2.x branch is end-of-life.

[ANNOUNCEMENT] Apache HTTP Server 2.4.68 Released
May 6, 20262mo ago

Striga publishes technical analysis of CVE-2026-23918

Striga published a detailed writeup explaining how two HTTP/2 frames on the same stream can trigger the mod_http2 double-free remotely over a single TCP connection. The research also described how the bug could be developed toward RCE on APR mmap allocator builds when paired with an information leak.

For a Fistful of Dollars: Less than $100 of Compute Surfaces Pre-auth RCE in Apache httpd

Apache releases HTTP Server 2.4.67 with fixes

Apache released version 2.4.67 to fix CVE-2026-23918 and other vulnerabilities. The fix for the mod_http2 issue deduplicates cleanup entries before adding them to the internal spurge array.

For a Fistful of Dollars: Less than $100 of Compute Surfaces Pre-auth RCE in Apache httpd

Apache bug 69899 reported as a stability issue

The underlying mod_http2 double-free issue was previously reported to Apache as Bugzilla 69899 in December 2025, but it was treated as a stability bug and did not receive a CVE at that time.

For a Fistful of Dollars: Less than $100 of Compute Surfaces Pre-auth RCE in Apache httpd
May 4, 20262mo ago

Apache discloses CVE-2026-23918

On 2026-05-04, Apache disclosed CVE-2026-23918 affecting Apache HTTP Server 2.4.66. The flaw is a mod_http2 double-free that can lead to denial of service and, under certain conditions, unauthenticated remote code execution.

Critical Vulnerability in Apache HTTP Server Disclosed (CVE-2026-23918)
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

10 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.