discovered 03 Aug 2026
CVE-2026-23918-Apache-H2-PoC
→ View on GitHubThis tool is a proof-of-concept exploit for the double-free vulnerability (CVE-2026-23918) in Apache's `mod_http2`, capable of inducing a denial-of-service (DoS) by repeatedly crashing server workers through a race condition in stream cleanup. It allows users to demonstrate this vulnerability's impact via various modes, including aggressive DoS and passive vulnerability detection, by manipulating how Apache handles early stream resets. While remote code execution (RCE) is theoretically possible, it requires multiple specific conditions, making reliable exploitation complex and unlikely for most attackers.