HIGH: Apache HTTP/2 Double-Free (CVE-2026-23918) Lets Two Frames DoS Your Web Server, RCE Already Demoed
Apache HTTP Server 2.4.66 ships a double-free in mod_http2 that crashes worker processes with two HTTP/2 frames and no authentication. CVSS 8.8, DoS exploitation already in the wild, and a public PoC chain converts the bug to remote code execution on default Debian and Docker builds. The fix is in 2.4.67, released May 4.