
Elite reconnaissance script for auditing Apache's HTTP/2 stack against memory corruption (CVE-2026-23918). Features ALPN protocol forcing and monochrome dashboard intelligence. Built for Blue Teams and Security Researchers.
Professional Intelligence & Reconnaissance Tool for Apache HTTP/2 Double-Free Vulnerability.
CVE-2026-23918 (CVSS 8.8) is a critical memory corruption flaw in Apache HTTP Server 2.4.66. This auditor is designed to safely fingerprint targets and assess risk exposure, especially in environments where version strings are obfuscated or shielded by WAFs.
| Feature | Description |
|---|---|
| ALPN Protocol Forcing | Mandates an HTTP/2 handshake to verify engine activation |
| WAF/Proxy Bypass | Optimized for direct Origin-IP auditing to bypass Cloudflare/Akamai |
| Risk Probability Scoring | Advanced logic to analyze hidden or "Apache-only" server headers |
| Neon High-Contrast UI | Professional terminal dashboard for clear intelligence reporting |
git clone https://github.com/qassam-315/CVE-2026-23918-Elite-Auditor.git
pip install "httpx[http2]" rich
💻 Usage Examples
Use this for checking standard web targets:
python3 cve_23918_elite.py -t https://example.com
Use this to scan the backend server directly, bypassing Cloudflare/WAF:
python3 cve_23918_elite.py -t https://11.11.111
📊 Technical Intelligence
The tool analyzes:
⚠️ Legal & Ethical Disclaimer
This tool is for Legal and Ethical Security Research only. It is a non-destructive scanner and does not contain any weaponized payload. The author (qassam-315) is not responsible for any misuse. Always obtain explicit authorization before testing any infrastructure.
Developed by: qassam-315 Branch: Cyber-Security Research & Intelligence Branch