PatchDay Alert

CVE

CVE-2026-23918

0field notes · 1digest CVSS 8.8


Daily digests

A double-free bug in Apache HTTP Server's HTTP/2 handling can be triggered when a client sends an early stream reset. This could lead to remote code execution. No authentication is required, and any internet-facing Apache instance with mod_http2 enabled is a target.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.