Dossier
CVE-2026-23918
Coverage of CVE-2026-23918 in the Nexus archive.
- Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
The Apache Software Foundation has released security updates to address several vulnerabilities in the HTTP Server, including a severe flaw that could lead to remote code execution. The vulnerability, tracked as CVE-2026-23918, has a CVSS score of 8.8 and is described as a case of double free and possible RCE in the HTTP/2 protocol handling. This issue enables DoS and potential RCE.