Impact
The flaw is a double free in Apache HTTP Server’s HTTP/2 implementation that can trigger arbitrary code execution if exploited. It handling (CWE‑415) and an early reset scenario (CWE‑1341). An attacker could potentially execute malicious code on the host if the vulnerability is triggered during an HTTP/2 session.
Affected Systems
Apache HTTP Server version 2.4.66, released by the Apache Software Foundation, contains the susceptibility. Upgrading to version 2.4.67 (or later) removes the buggy code path and resolves the vulnerability.
Risk and Exploitability
The likely attack vector for this vulnerability is an HTTP/2 connection initiated from an external client. An attacker would need to trigger the bug through an early reset scenario within that protocol. Given a CVSS score of 8.8, the vulnerability is considered high severity, and the EPSS score of 50% indicates a fairly large likelihood of exploitation in the current threat landscape. The vulnerability is not listed in CISA’s KEV catalog. If successfully exploited, the double free could lead to arbitrary code execution on the affected server.
OpenCVE Enrichment
Debian DSA
Ubuntu USN