Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
https://www.helpnetsecurity.com/2026/05/18/debian-13-5-released/
https://thehackernews.com/2026/05/critical-apache-http2-flaw-cve-2026.html
https://github.com/smadonkuan/CVE-LAb
https://github.com/insomnisec/public_cve_detections
https://github.com/sibersan/apache_audit_cve-2026-23918
https://github.com/barmi/cve-patch-auditor
https://github.com/insomnisec/Detections-CVE-2026-23918
https://github.com/alt3kx/CVE-2026-23918
https://github.com/hackervlogofficial/CVE-2026-23918
https://github.com/seguridadentrerios/CVE-2026-23918
https://github.com/aa022/CVE-2026-23918-Passive-Audit
https://github.com/rshosting/Apache-CVE-2026-23918-fix
https://github.com/qassam-315/CVE-2026-23918-Elite-Auditor
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23918.json
https://bugzilla.redhat.com/show_bug.cgi?id=2465304