CVE-2026-23918: Apache HTTP/2 Double-Free Enables DoS and Remote Code Execution
A double-free vulnerability in Apache HTTP Server 2.4.66's mod_http2 module (CVSS 8.8) allows unauthenticated attackers to crash worker processes with just two HTTP/2 frames, and escalate to full RCE.
May 9, 2026 | 10 min read | Xentrika Team