Back

HIGH

Apache HTTP Server: http2: double free and possible RCE on early reset

Published May 4, 2026

Description

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.

This issue affects Apache HTTP Server: 2.4.66.

Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Affected products

Remediation

Red Hat statement

This issue marked as Important rather than Moderate because it involves a memory safety violation (double free) in the HTTP/2 request handling path, which is directly exposed to untrusted network input. A double free condition can corrupt the heap allocator’s internal metadata, enabling attackers to manipulate memory layout and potentially achieve arbitrary code execution (RCE) under favorable conditions. In this case, the flaw is triggered during an early stream reset in HTTP/2, meaning it can be exercised pre-authentication by a remote client without requiring complex application-level interaction. Given that Apache HTTP Server is widely deployed in internet-facing environments, even a low-probability RCE path significantly elevates risk.

Red Hat mitigation

To mitigate this issue, disable the `mod_http2` module in your Apache HTTP Server configuration. This can be achieved by commenting out or removing the `LoadModule http2_module modules/mod_http2.so` line in the Apache configuration file (e.g., `/etc/httpd/conf.modules.d/00-base.conf` or a similar configuration file). After modifying the configuration, restart the httpd service for the changes to take effect. This action will impact services relying on HTTP/2 functionality.

Weaknesses (2)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published May 4, 2026
Updated Jul 15, 2026
Reserved Jan 19, 2026
CISA Vulnrichment
Updated May 4, 2026
NVD
Status Modified
Modified Jul 15, 2026
Red Hat
Severity Important
Public date May 4, 2026
ENISA EUVD
Assigner apache
Published May 4, 2026
Updated Jul 15, 2026
Exploited since n/a
EUVD-2026-26955