suse · CVE-2026-23918

Quick triage

Priority: high Published: 2026-05-04 23:17:08 UTC Updated: 2026-05-04 23:17:08 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2026-23918 severity important: SUSE including 7 source package names (apache2, apache2-devel, …), 77 product×package rows across 18 product lines (SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS, SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS, … (18 product lines)): Known Not Affected 77.

Description:

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

cvelogic Threat Intelligence