ctipilot.ch

Apache HTTP Server 2.4.66 — HTTP/2 double-free RCE (CVSS 8.8)

cve · CVE-2026-23918

Coverage timeline
2
first 2026-05-06 → last 2026-05-10
Briefs
2
2 distinct
Sources cited
22
19 hosts
Sections touched
2
active_vulns, weekly_summary
Co-occurring entities
0
no co-occurrence

Story timeline

  1. 2026-05-10CTI Weekly Summary — 2026-W19 (May 04 – May 10, 2026)
    weekly_summaryConsolidated in weekly summary for week 2026-W19
  2. 2026-05-06CTI Daily Brief — 2026-05-06
    active_vulnsFirst coverage. Double-free in mod_http2 on early stream reset; DoS trivial, RCE requires APR mmap allocator (default Debian/Docker); PoC confirmed; fixed in Apache 2.4.67.

Where this entity is cited

  • active_vulns1
  • weekly_summary1

Source distribution

  • github.com4 (18%)
  • attack.mitre.org1 (5%)
  • badhost.org1 (5%)
  • blog.calif.io1 (5%)
  • cert.pl1 (5%)
  • cert.ssi.gouv.fr1 (5%)
  • cve.threatint.eu1 (5%)
  • httpd.apache.org1 (5%)
  • other11 (50%)

External references

NVD · cve.org · CISA KEV

All cited sources (22)

Items in briefs about Apache HTTP Server 2.4.66 — HTTP/2 double-free RCE (CVSS 8.8)

No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.