CVE-2026-23918
EUVD-2026-2695504.05.2026, 15:16
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | http_server | 2.4.66 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| apache2 |
| ||||||||
| apache2-devel |
| ||||||||
| apache2-manual |
| ||||||||
| apache2-prefork |
| ||||||||
| apache2-utils |
| ||||||||
| apache2-worker |
|
Amazon Linux Releases
Common Weakness Enumeration
Vulnerability Media Exposure