
Reglas de detección para CVE-2026-23918 Apache http2 RCE - Crédito: stringa.ai, isec.pl
Publicado: 2026-05-04
CVSSv3: 8.8 (Alta)
Tipo: Ejecución Remota de Código / Denegación de Servicio (Corrupción de Memoria por Doble Liberación)
Apache HTTP Server ( ruta de limpieza de flujo)
Apache HTTP Server 2.4.66 con HTTP/2 habilitado y MPM multi-hilo
mod_http2h2_mplx.cCVE-2026-23918 es una vulnerabilidad de corrupción de memoria por doble liberación en la implementación del protocolo HTTP/2 de Apache HTTP Server 2.4.66, que afecta solo a la ruta de limpieza de flujo del módulo mod_http2 en h2_mplx.c. Permite que un atacante remoto no autenticado provoque un bloqueo de los procesos workers de Apache (Denegación de Servicio) con una sola conexión TCP y dos tramas HTTP/2. Bajo condiciones presentes en sistemas derivados de Debian e imágenes oficiales de Apache Docker, la doble liberación puede convertirse en una Ejecución Remota de Código completa.
La explotación de DoS ha sido confirmada en entornos reales. Se han observado escaneos a gran escala en Internet dirigidos a endpoints HTTP/2. El exploit de RCE ha demostrado ser viable en entornos controlados, aunque no hay evidencia de explotación pública generalizada para RCE en este momento.
MPM prefork no se ve afectado — la vulnerabilidad requiere una configuración MPM multi-hilo (worker, event o similar). CVE-2026-23918 afecta solo a Apache HTTP Server versión 2.4.66.
Attacker opens HTTP/2 connection to Apache 2.4.66 (mod_http2 loaded, multi-threaded MPM) └─ Sends HTTP/2 HEADERS frame on stream N (opens the stream) └─ Immediately sends RST_STREAM on stream N (non-zero error code) └─ Sent BEFORE the multiplexer has registered the stream
Two nghttp2 callbacks fire in sequence: ├─ on_frame_recv_cb (RST received) → calls h2_mplx_c1_client_rst → m_stream_cleanup └─ on_stream_close_cb (stream closed) → calls h2_mplx_c1_client_rst → m_stream_cleanup
Result: same h2_stream pointer pushed onto spurge[] cleanup array TWICE
c1_purge_streams() iterates spurge[] and calls h2_stream_destroy() on each entry: ├─ First call: valid — frees the stream └─ Second call: DOUBLE-FREE — operates on already-freed memory → heap corruption
DoS path (trivial, in the wild): └─ Heap corruption → SIGABRT in worker process → worker dies → service disruption
RCE path (requires mmap allocator — default on Debian/Ubuntu and official Docker): └─ Attacker places fake h2_stream struct at freed virtual address via mmap reuse └─ Points pool cleanup function pointer to system() └─ Uses Apache scoreboard shared memory (fixed address, ASLR-resistant) as payload container └─ c1_purge_streams() executes system() with attacker-controlled argument → RCE
> **Asimetría clave:** La ruta de denegación de servicio no requiere habilidad de manipulación del montón y está siendo explotada activamente. La ruta de ejecución remota de código es técnicamente exigente, pero se ha demostrado en condiciones de laboratorio y casi con toda seguridad será armada en un futuro próximo, dado que la tabla de puntuaciones tiene una dirección fija resistente a ASLR.
---
## Arquitectura de detección
> Esta sección explica por qué las herramientas de detección aquí difieren sustancialmente de un paquete típico de escalada de privilegios local.
Copy Fail (CVE-2026-31431) era una vulnerabilidad **del lado del host, posterior al acceso**. El atacante necesitaba presencia existente en el sistema. La detección residía principalmente en la capa de llamadas al sistema (auditd, Wazuh) con escaneo YARA del script PoC en disco.
CVE-2026-23918 es una vulnerabilidad **del lado de la red, previa al acceso**. El exploit llega como tramas del protocolo HTTP/2 a través de la red antes de que se ejecute cualquier código de aplicación. Esto desplaza significativamente la pila de detección:
| Capa | Copy Fail (LPE) | CVE-2026-23918 (RCE) |
|---|---|---|
| **Detección primaria** | Reglas syscall de auditd | Reglas de red de Suricata |
| **WAF (ModSecurity)** | Limitado — no puede ver el exploit | Relevante — anomalía + post-explotación |
| **Auditd** | Detección central | Detección de resultados (caídas, post-explotación) |
| **YARA** | Escanea script PoC | Escanea webshells (artefactos post-explotación) |
| **IDS de red** | No aplica | Capa de detección de primera clase |
| **Inspección TLS** | N/A | Requerida para cobertura completa de Suricata |
La regla general: para RCE a nivel de red, trabajar de afuera hacia adentro (red → WAF → host). Para escalada de privilegios local, trabajar desde el host hacia afuera.
---
## Limitaciones de la detección
> **Lea esto antes de implementar cualquier regla.**
**1. TLS termina la visibilidad de HTTP/2.**
La mayoría de las implementaciones de Apache en producción sirven HTTPS. Suricata no puede inspeccionar el contenido de las tramas HTTP/2 cifradas sin que se configure el descifrado TLS. Si su implementación de Suricata no tiene acceso a las claves de sesión TLS o a un espejo de descifrado, las reglas a nivel de red a continuación solo detectarán:
- HTTP/2 en texto claro (h2c) — poco común en producción pero presente en entornos internos
- La firma de red del comportamiento de la conexión TCP (recuento de conexiones, patrones RST en la capa TCP)
Para implementaciones HTTPS, habilite el descifrado TLS de Suricata mediante la configuración `tls-decrypt` y el registro de claves de sesión, o confíe en el WAF (ModSecurity/Coraza) y las capas basadas en host (auditd/Wazuh) en su lugar.
**2. ModSecurity no puede bloquear el desencadenante del exploit.**
La doble liberación ocurre dentro del analizador de tramas HTTP/2, antes de que se ensamble una solicitud HTTP completa y se pase a ModSecurity. El WAF ve la solicitud solo después de que se completa el análisis de la trama — momento en el cual el daño ya puede haberse producido. ModSecurity en este paquete se utiliza para detección de anomalías, limitación de velocidad y detección posterior a la explotación, no como bloqueador del desencadenante.
**3. MPM prefork no se ve afectado.**
Si su implementación de Apache utiliza `mpm_prefork_module` (monohilo), esta vulnerabilidad no aplica. El error solo se manifiesta en MPMs multihilo (`mpm_event_module` o `mpm_worker_module`). Verifique con `apachectl -V | grep MPM` antes de implementar reglas que producirían falsos positivos en servidores prefork.
**4. La RCE requiere el asignador mmap.**
La ruta de RCE (no la ruta de DoS) requiere el asignador mmap de APR, que es el predeterminado en distribuciones derivadas de Debian e imágenes oficiales de Apache Docker. Las implementaciones basadas en RHEL/CentOS que usan jemalloc o system malloc tienen un riesgo reducido de RCE, pero aún son completamente vulnerables a DoS.
**5. No hay IoCs estables posteriores a la explotación aún.**
Al momento de escribir esto, no existen IoCs publicados por proveedores para actividad posterior a la explotación. Las reglas YARA y las reglas auditd dirigidas al comportamiento posterior a la explotación se basan en patrones generales de webshell y escalada de privilegios — detectarán resultados comunes pero no una carga útil sofisticada y hecha a medida.
---
## Mitigación inmediata
Aplicar en orden de preferencia. Cada una es más disruptiva que la anterior, pero cada una es más completa.```bash
# Option 1 (Preferred): Upgrade to 2.4.67
# See Patching & Remediation section below
# Option 2: Disable HTTP/2 in Apache config (no reboot required, restart required)
# In httpd.conf or relevant VirtualHost / site config:
# Remove or comment out: Protocols h2 h2c http/1.1
# Replace with: Protocols http/1.1
# Then:
apachectl configtest && sudo systemctl restart apache2
# Option 3: Switch to MPM prefork (eliminates vulnerability entirely — more disruptive)
sudo a2dismod mpm_event mpm_worker
sudo a2enmod mpm_prefork
apachectl configtest && sudo systemctl restart apache2
# Option 4: Reverse proxy HTTP/2 termination
# If nginx, HAProxy, or a CDN is in front of Apache and terminates HTTP/2,
# Apache only receives HTTP/1.1 — confirm your proxy config explicitly:
# nginx: proxy_http_version 1.1; (already the default for upstream connections)
# HAProxy: use-server-close + http/1.1 on backend bind
# Verify with: curl -v --http2 https://your-origin-directly
Verifica tu mitigación: Después de deshabilitar HTTP/2, confirma con:
curl -s -o /dev/null -w "%{http_version}" --http2 http://localhost/ # Debería devolver "1.1", no "2" apachectl -M | grep http2 # No debería producir ninguna salida
Guárdalo como cve-2026-23918.rules y referéncialo desde suricata.yaml.
Requisitos previos:
- Suricata 6.0+ para soporte de las palabras clave
http2.frametype/http2.errorcode(se recomienda Suricata 7.x)app-layer.protocols.http2.enabled: yesensuricata.yaml
$HTTP_SERVERSvariable configurada para incluir tus hosts Apache- Los SID a continuación son ejemplos — ajústalos a tu política local de SID```
alert http2 $EXTERNAL_NET any -> $HTTP_SERVERS any
(msg:"CVE-2026-23918 Apache mod_http2 Double-Free - RST_STREAM with non-zero error code";
flow:established,to_server;
http2.frametype:3;
http2.errorcode:!0;
classtype:web-application-attack;
reference:cve,2026-23918;
sid:9926231801; rev:1;)
alert http2 $EXTERNAL_NET any -> $HTTP_SERVERS any
(msg:"CVE-2026-23918 Apache mod_http2 Double-Free - RST_STREAM flood (active DoS/exploit scan)";
flow:established,to_server;
http2.frametype:3;
http2.errorcode:!0;
threshold: type both, track by_src, count 10, seconds 30;
classtype:denial-of-service;
reference:cve,2026-23918;
sid:9926231802; rev:1;)
alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS [80,8080,8000,8443]
(msg:"CVE-2026-23918 Apache mod_http2 - HTTP/2 RST_STREAM frame detected (cleartext)";
flow:established,to_server;
content:"|00 00 04 03 00|"; depth:5; offset:0;
threshold: type both, track by_src, count 5, seconds 30;
classtype:web-application-attack;
reference:cve,2026-23918;
sid:9926231803; rev:1;)
alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS [80,8080,8000]
(msg:"CVE-2026-23918 Apache mod_http2 - HTTP/2 client preface with rapid RST_STREAM (exploit pattern)";
flow:established,to_server;
content:"PRI * HTTP/2.0|0d 0a 0d 0a|SM|0d 0a 0d 0a|"; depth:24; offset:0;
content:"|00 00 04 03|"; distance:0; within:512;
classtype:web-application-attack;
reference:cve,2026-23918;
sid:9926231804; rev:1;)
alert http $HTTP_SERVERS any -> $EXTERNAL_NET any
(msg:"CVE-2026-23918 Apache 2.4.66 version string in response - vulnerable version exposed";
flow:established,to_client;
http.header; content:"Apache/2.4.66";
classtype:policy-violation;
reference:cve,2026-23918;
sid:9926231805; rev:1;)
alert tcp $HTTP_SERVERS [80,443,8080,8443] -> $EXTERNAL_NET ![$HTTP_PORTS,443,80]
(msg:"CVE-2026-23918 Apache possible post-RCE reverse shell - outbound from web server port";
flow:established,to_server;
classtype:trojan-activity;
reference:cve,2026-23918;
sid:9926231806; rev:1;)
### Notas de Ajuste
Después de desplegar en modo `alert` durante 24–48 horas, revise los aciertos en las Reglas 3 y 4 — los clientes HTTP/2 legítimos pueden activarlas en entornos de alto tráfico. Si la Regla 1 (capa de aplicación) está captando suficiente señal, las Reglas 3 y 4 pueden trasladarse a menor severidad o eliminarse.
Para implementaciones de Suricata con límites de `stream-depth`, asegúrese de que el patrón de prefacio HTTP/2 en la Regla 4 caiga dentro de la ventana de inspección.
---
## Configuración de ModSecurity / Coraza
> **Requisitos previos:**
> - ModSecurity 2.x (`libapache2-mod-security2`) o [Coraza](https://coraza.io/) (sucesor compatible, mantenido activamente)
> - OWASP Core Rule Set (CRS) 4.x recomendado: [coreruleset.org/installation](https://coreruleset.org/installation/)
> - `SecRuleEngine On` (o `DetectionOnly` para modo solo registro durante el ajuste inicial)
### Por qué ModSecurity es relevante aquí (pero no suficiente)
Como se señaló en la sección Limitaciones de Detección, ModSecurity no puede interceptar el desencadenante de double-free porque el exploit opera en la capa de tramas HTTP/2. Sin embargo, ModSecurity proporciona tres capas significativas de valor para este CVE:
1. **Límite de velocidad** — ralentiza el escaneo DoS automatizado y aumenta el costo de la fuerza bruta del heap spray para RCE
2. **Detección posterior a la explotación** — si se logra RCE, el atacante intentará desplegar un web shell o ejecutar comandos; ModSecurity puede detectar ambos
3. **Puntuación de anomalías de OWASP CRS** — los encabezados malformados y patrones de conexión asociados con la explotación pueden puntuar de manera anómala bajo CRS Paranoia Level 2+
### Fortalecimiento de la configuración de Apache (aplicar junto con ModSecurity)
Añadir a `httpd.conf` o un archivo de inclusión. Estas son directivas de Apache, no reglas de ModSecurity, pero reducen la superficie de ataque HTTP/2:```apache
# ============================================================
# CVE-2026-23918 Apache HTTP/2 Hardening Directives
# ============================================================
# Limit concurrent streams per HTTP/2 session.
# The exploit typically uses 1 stream, but limiting sessions
# reduces the rate at which a single client can attempt the trigger.
H2MaxSessionRequests 100
# Restrict H2 stream push (unused surface, reduce complexity)
H2Push Off
# Suppress version information in Server headers.
# Prevents trivial identification of vulnerable 2.4.66 instances.
ServerTokens Prod
ServerSignature Off
# Constrain HTTP/2 window size — reduces memory available for heap spray
H2WindowSize 65535
# If HTTP/2 is not required at all:
# Protocols http/1.1
Guarda estas en tu archivo de reglas personalizadas de ModSecurity (e.g., /etc/modsecurity/cve-2026-23918.conf):```apache
SecAction
"id:9923918001,
phase:1,
nolog,
pass,
initcol:ip=%{REMOTE_ADDR},
setvar:ip.http2_requests=+1,
expirevar:ip.http2_requests=60"
SecRule ip:http2_requests "@gt 30"
"id:9923918002,
phase:1,
deny,
status:429,
log,
msg:'CVE-2026-23918: Rate limit exceeded - possible DoS/exploit scan',
tag:'CVE-2026-23918',
tag:'OWASP_CRS/DoS',
severity:'CRITICAL'"
SecAction
"id:9923918003,
phase:1,
nolog,
pass,
initcol:ip=%{REMOTE_ADDR}"
SecRule RESPONSE_STATUS "@rx ^(4|5)[0-9]{2}"
"id:9923918004,
phase:5,
nolog,
pass,
setvar:ip.error_count=+1,
expirevar:ip.error_count=120"
SecRule ip:error_count "@gt 20"
"id:9923918005,
phase:1,
log,
pass,
msg:'CVE-2026-23918: Elevated error rate from source IP - possible exploit scanning',
tag:'CVE-2026-23918',
severity:'WARNING'"
SecRule REQUEST_BODY
"@rx (?:system|exec|passthru|shell_exec|popen|proc_open)\s*(\s*(?:$_(?:GET|POST|REQUEST|COOKIE)|base64_decode)"
"id:9923918010,
phase:2,
deny,
status:403,
log,
msg:'CVE-2026-23918: Possible web shell command execution in POST body',
tag:'CVE-2026-23918',
tag:'WEBSHELL',
severity:'CRITICAL'"
SecRule ARGS
"@rx (?:(?:^|[;&|`])\s*(?:id|whoami|uname|cat\s+/etc|ls\s+/|pwd|wget\s+http|curl\s+http|bash\s+-[ci]|nc\s+-[el]|python[23]?\s+-c|perl\s+-e|ruby\s+-e))"
"id:9923918011,
phase:2,
deny,
status:403,
log,
msg:'CVE-2026-23918: OS command injection pattern in request arguments - possible post-exploit web shell',
tag:'CVE-2026-23918',
tag:'WEBSHELL',
severity:'CRITICAL'"
SecRule FILES_TMPNAMES "@inspectFile /etc/modsecurity/util/php-filter.pm"
"id:9923918012,
phase:2,
log,
deny,
status:403,
msg:'CVE-2026-23918: PHP code detected in file upload - possible web shell deployment',
tag:'CVE-2026-23918',
tag:'WEBSHELL',
severity:'CRITICAL'"
SecRule REQUEST_BODY|ARGS
"@rx (?:bash\s+-i\s+>&?\s*/dev/tcp|/dev/tcp/[0-9]{1,3}.[0-9]{1,3}|nc\s+(?:-e|-c)\s+/bin/(?:bash|sh)|python[23]?\s+-c\s+['"]import\s+socket)"
"id:9923918013,
phase:2,
deny,
status:403,
log,
msg:'CVE-2026-23918: Reverse shell pattern in request - possible post-exploit activity',
tag:'CVE-2026-23918',
tag:'REVERSE_SHELL',
severity:'CRITICAL'"
### Recomendación de ajuste de OWASP CRS
Para obtener la señal de anomalía más alta sin falsos positivos excesivos, implemente CRS en el Nivel de Paranoia 2 con la puntuación de anomalías habilitada. El comportamiento de conexión desencadenante (HTTP/2 malformado que genera errores de retroceso a HTTP/1.x, reinicios repetidos) acumulará puntuación de anomalía bajo las reglas CRS 920xxx y 921xxx y puede superar el umbral predeterminado `inbound_anomaly_score_threshold` de 5, generando alertas sin reglas personalizadas.
---
## Reglas de Auditd
Guardar como `/etc/audit/rules.d/cve-2026-23918.rules`
Recargar con: `sudo augenrules --load`
> **Principio de diseño:** Debido a que el desencadenante del exploit reside en la capa de análisis HTTP/2 de red/kernel, auditd no puede capturar el desencadenante en sí. Estas reglas detectan:
> 1. El **resultado** de la explotación DoS (señales de caída del trabajador de Apache)
> 2. **Actividad posterior a la explotación** si se logra RCE (ejecución de shell, escrituras de archivos, conexiones salientes por parte del usuario de Apache)```bash
## ============================================================
## CVE-2026-23918 Apache HTTP/2 Double-Free — Auditd Rules
## ============================================================
## These rules detect the CONSEQUENCES of exploitation, not the
## trigger. The trigger is a network protocol event and is
## detected by Suricata. These rules catch:
## 1. Apache worker process crashes (DoS outcome)
## 2. Shell execution by the web server user (RCE outcome)
## 3. Web root file creation (web shell deployment)
## 4. Outbound network connections by web server process (reverse shell)
##
## Distribution notes for UID values:
## - Debian/Ubuntu: www-data = uid 33
## - RHEL/Rocky/CentOS: apache = uid 48
## Adjust -F uid= values for your distribution. Use `id www-data`
## or `id apache` to confirm the UID on your systems.
## ============================================================
## --- Apache worker SIGABRT detection (DoS exploitation outcome) ---
## A double-free that reaches the crash path generates SIGABRT (signal 6).
## Monitoring kill() syscalls with a1=6 (SIGABRT) targets abnormal process
## termination, which Apache itself triggers on double-free detection.
## Correlate with Apache error log entries (child exited with signal 6).
-a always,exit -F arch=b64 -S kill -F a1=6 -k cve_2026_23918_sigabrt
-a always,exit -F arch=b32 -S kill -F a1=6 -k cve_2026_23918_sigabrt
## --- SIGSEGV monitoring (alternative crash path) ---
## Depending on heap state, the double-free may produce a SIGSEGV (signal 11)
## rather than SIGABRT. Both are abnormal for production Apache workers.
-a always,exit -F arch=b64 -S kill -F a1=11 -k cve_2026_23918_sigsegv
-a always,exit -F arch=b32 -S kill -F a1=11 -k cve_2026_23918_sigsegv
## --- Shell execution by web server user (RCE outcome - Debian/Ubuntu) ---
## If RCE is achieved via the mmap allocator path, the attacker's payload
## runs as the Apache worker user (www-data on Debian/Ubuntu, uid=33).
## Legitimate Apache does not exec() a shell. Any execve() of bash/sh/dash
## by www-data is anomalous and warrants immediate investigation.
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/bin/bash -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/bin/sh -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/bin/dash -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/usr/bin/python3 -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/usr/bin/perl -k cve_2026_23918_rce_shell_deb
## --- Shell execution by web server user (RCE outcome - RHEL/Rocky, uid=48) ---
-a always,exit -F arch=b64 -S execve -F uid=48 -F exe=/bin/bash -k cve_2026_23918_rce_shell_rhel
-a always,exit -F arch=b64 -S execve -F uid=48 -F exe=/bin/sh -k cve_2026_23918_rce_shell_rhel
## --- Web root file creation (web shell deployment) ---
## Post-RCE, the most common next step is writing a persistent web shell.
## Monitor web root directories for new file creation and write operations.
## Adjust paths for your DocumentRoot configuration.
-w /var/www/html -p wa -k cve_2026_23918_webroot_write
-w /var/www -p wa -k cve_2026_23918_webroot_write
-w /srv/www -p wa -k cve_2026_23918_webroot_write
-w /usr/share/apache2/default-site -p wa -k cve_2026_23918_webroot_write
## --- Outbound network connections by web server user (reverse shell) ---
## Apache workers do not normally initiate outbound TCP connections.
## connect() syscalls by www-data/apache indicate post-exploitation activity.
-a always,exit -F arch=b64 -S connect -F uid=33 -k cve_2026_23918_apache_outbound_deb
-a always,exit -F arch=b64 -S connect -F uid=48 -k cve_2026_23918_apache_outbound_rhel
## --- Apache config and module modification (persistence) ---
## An attacker with RCE may attempt to persist by modifying Apache config
## or dropping a malicious module. Watch for writes to config directories.
-w /etc/apache2 -p wa -k cve_2026_23918_apache_config
-w /etc/httpd -p wa -k cve_2026_23918_apache_config
-w /etc/apache2/mods-enabled -p wa -k cve_2026_23918_apache_mods
Después de la implementación, use este comando de una línea ausearch para buscar secuencias de fallo-luego-shell:```bash
sudo ausearch -k cve_2026_23918_sigabrt
-k cve_2026_23918_rce_shell_deb
-k cve_2026_23918_rce_shell_rhel
-k cve_2026_23918_webroot_write
--start yesterday -i
sudo ausearch -k cve_2026_23918_rce_shell_deb --start today -i | grep -A5 "exe="
---
## Reglas de Wazuh
Guárdalo como un archivo de reglas personalizado (por ejemplo, `/var/ossec/etc/rules/local_rules.xml`).
> **Requisitos previos:**
> - Reglas de Auditd desplegadas arriba y decodificador de auditd de Wazuh activo
> - Registro de errores de Apache (`/var/log/apache2/error.log` o `/var/log/httpd/error_log`) agregado a los archivos monitoreados de Wazuh
> - Registro de acceso de Apache monitoreado para patrones de error de conexión HTTP/2```xml
<!-- ==============================================================
CVE-2026-23918 Apache HTTP/2 Double-Free — Wazuh Rules
Requires:
- auditd rules from cve-2026-23918.rules deployed
- Apache error log monitored by Wazuh agent
============================================================== -->
<!-- Level 10: Apache worker crash signal (SIGABRT) detected via auditd -->
<rule id="113001" level="10">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_sigabrt</field>
<description>CVE-2026-23918: SIGABRT sent to process — possible Apache worker double-free crash (DoS exploitation)</description>
<group>cve,denial_of_service,apache,http2,</group>
</rule>
<!-- Level 10: SIGSEGV variant crash path -->
<rule id="113002" level="10">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_sigsegv</field>
<description>CVE-2026-23918: SIGSEGV sent to process — possible Apache worker memory corruption crash</description>
<group>cve,denial_of_service,apache,http2,</group>
</rule>
<!-- Level 14 CRITICAL: Multiple worker crashes in short window — active DoS -->
<rule id="113003" level="14" frequency="3" timeframe="60">
<if_matched_sid>113001</if_matched_sid>
<description>CVE-2026-23918 CRITICAL: Multiple Apache worker SIGABRT crashes within 60 seconds — active DoS exploitation in progress</description>
<group>cve,denial_of_service,apache,http2,high_confidence,</group>
</rule>
<!-- Level 15 CRITICAL: Shell execution by web server user — RCE achieved -->
<rule id="113004" level="15">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_rce_shell_deb|cve_2026_23918_rce_shell_rhel</field>
<description>CVE-2026-23918 CRITICAL: Shell executed by web server user (www-data/apache) — RCE likely achieved, immediate incident response required</description>
<group>cve,rce,privilege_escalation,apache,http2,high_confidence,</group>
</rule>
<!-- Level 14 CRITICAL: Web shell written to web root -->
<rule id="113005" level="14">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_webroot_write</field>
<description>CVE-2026-23918: File written to web root directory — possible web shell deployment post-RCE</description>
<group>cve,rce,webshell,apache,</group>
</rule>
<!-- Level 13 CRITICAL: Outbound connection by Apache worker process -->
<rule id="113006" level="13">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_apache_outbound_deb|cve_2026_23918_apache_outbound_rhel</field>
<description>CVE-2026-23918: Outbound TCP connection by web server user — possible reverse shell post-RCE</description>
<group>cve,rce,reverse_shell,apache,</group>
</rule>
<!-- Level 14: RCE shell followed by outbound connection (reverse shell confirmed) -->
<rule id="113007" level="14">
<if_matched_sid>113004</if_matched_sid>
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_apache_outbound_deb|cve_2026_23918_apache_outbound_rhel</field>
<description>CVE-2026-23918 CRITICAL: Shell execution AND outbound connection by web server user — reverse shell active</description>
<group>cve,rce,reverse_shell,apache,high_confidence,</group>
</rule>
<!-- Level 12: Apache config modified (persistence attempt) -->
<rule id="113008" level="12">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_apache_config|cve_2026_23918_apache_mods</field>
<description>CVE-2026-23918: Apache config or module directory modified — possible attacker persistence attempt</description>
<group>cve,rce,persistence,apache,</group>
</rule>
<!-- Level 10: Apache error log — child process crash (log-based correlation) -->
<!-- Requires Apache error log monitored by Wazuh, decoded via apache decoder -->
<rule id="113009" level="10">
<decoded_as>apache-errorlog</decoded_as>
<match>child pid \d+ exit signal Aborted|child process \d+ still did not exit|segmentation fault</match>
<description>CVE-2026-23918: Apache child process crash in error log — possible double-free DoS exploitation</description>
<group>cve,denial_of_service,apache,http2,</group>
</rule>
<!-- Level 13: Multiple Apache child crashes in error log + auditd SIGABRT (high confidence) -->
<rule id="113010" level="13">
<if_matched_sid>113009</if_matched_sid>
<if_matched_sid>113001</if_matched_sid>
<description>CVE-2026-23918: Apache error log crash + auditd SIGABRT — high-confidence active DoS, investigate immediately</description>
<group>cve,denial_of_service,apache,http2,high_confidence,</group>
</rule>
Guárdalo como cve_2026_23918.yar
Nota importante sobre el alcance: A diferencia de Copy Fail (CVE-2026-31431), YARA no puede detectar el disparador de explotación de esta vulnerabilidad. El disparador son dos tramas HTTP/2 sin procesar enviadas a través de una conexión de red — no hay ningún script o archivo que escanear. Las reglas YARA a continuación apuntan a:
- Web shells post-explotación que pueden desplegarse después de un RCE exitoso
- One-liners de reverse shell y cargas útiles codificadas en archivos accesibles por web
- La propia herramienta de explotación si está presente en un host pivote o servidor de preparación del atacante
Ámbito de escaneo recomendado: directorios raíz web (
/var/www/,/srv/www/), directorios temporales de Apache (/tmp/,/var/tmp/), y archivos creados recientemente propiedad dewww-dataoapache.```yara rule CVE_2026_23918_PostExploit_PHP_WebShell { meta: description = "Post-exploitation PHP web shell — possible CVE-2026-23918 outcome" author = "Detection Engineering" reference = "https://insomnisec.com/posts/2026-05-05-cve-2026-23918-apache-http2-rce_v2/" cve = "CVE-2026-23918" date = "2026-05-08" severity = "Critical" note = "Not specific to CVE-2026-23918 trigger — detects likely post-exploitation artifacts"
strings:
$php_open = "<?php" ascii nocase
$php_short = "<?" ascii nocase
// OS command execution functions
$sys = "system(" ascii nocase
$exec = "exec(" ascii nocase
$passthru = "passthru(" ascii nocase
$shell_exec = "shell_exec(" ascii nocase
$popen = "popen(" ascii nocase
$proc_open = "proc_open(" ascii nocase
// Parameter sourcing — required for command injection
$get_param = "$_GET[" ascii
$post_param = "$_POST[" ascii
$req_param = "$_REQUEST[" ascii
$cookie_param = "$_COOKIE[" ascii
$server_param = "$_SERVER[" ascii
// Obfuscation patterns common in web shells
$b64decode = "base64_decode(" ascii nocase
$str_rot13 = "str_rot13(" ascii nocase
$gzinflate = "gzinflate(" ascii nocase
$eval_call = "eval(" ascii nocase
// Common web shell capability strings
$phpinfo = "phpinfo()" ascii nocase
$file_put = "file_put_contents(" ascii nocase
condition:
filesize < 512KB and
(
// Classic command web shell: PHP + execution function + parameter input
($php_open or $php_short) and
any of ($sys, $exec, $passthru, $shell_exec, $popen, $proc_open) and
any of ($get_param, $post_param, $req_param, $cookie_param)
)
or
(
// Obfuscated web shell: eval + decode chain
($php_open or $php_short) and
$eval_call and
any of ($b64decode, $str_rot13, $gzinflate)
)
}
rule CVE_2026_23918_PostExploit_ReverseShell_InFile { meta: description = "Reverse shell one-liner in web-accessible file — possible post-RCE persistence" author = "Detection Engineering" cve = "CVE-2026-23918" date = "2026-05-08" severity = "Critical" note = "Scan web directories and /tmp; may also appear in crontabs and rc.local"
strings:
// Bash TCP reverse shell
$bash_tcp = "/dev/tcp/" ascii
$bash_rev = "bash -i >&" ascii nocase
// Netcat reverse shell
$nc_e = "nc -e /bin/" ascii nocase
$nc_c = "nc -c /bin/" ascii nocase
$ncat_e = "ncat -e /bin/" ascii nocase
// Python reverse shell
$py_socket = "import socket,subprocess" ascii
$py_pty = "import pty;pty.spawn" ascii
// Perl reverse shell
$perl_rev = "perl -e 'use Socket" ascii
// Common reverse shell via curl/wget pipe to bash
$curl_bash = "curl http" ascii
$wget_bash = "wget -O- http" ascii
$bash_pipe = "|bash" ascii
condition:
filesize < 1MB and
(
($bash_tcp and $bash_rev)
or ($nc_e or $nc_c or $ncat_e)
or ($py_socket and $py_pty)
or $perl_rev
or ($curl_bash and $bash_pipe)
or ($wget_bash and $bash_pipe)
)
}
rule CVE_2026_23918_ExploitTool_Artifacts { meta: description = "CVE-2026-23918 exploit tool artifacts — for scanning attacker staging hosts or memory dumps" author = "Detection Engineering" reference = "https://hadrian.io/blog/cve-2026-23918-apache-http-server-double-free-rce-in-http-2-implementation" cve = "CVE-2026-23918" date = "2026-05-08" severity = "High" note = "Matches known PoC tool strings — not expected in production Apache environments"
strings:
// h2_mplx.c specific identifier from public PoC analysis
$mplx_ref = "h2_mplx_c1_client_rst" ascii
$spurge_ref = "c1_purge_streams" ascii
$stream_ref = "h2_stream_destroy" ascii
// CVE reference strings that appear in PoC tools
$cve_str = "CVE-2026-23918" ascii
$version_target = "Apache/2.4.66" ascii
// HTTP/2 HEADERS + RST_STREAM frame bytes (common in PoC HTTP/2 libraries)
// HTTP/2 HEADERS frame header: type=0x01
$h2_headers_frame = { 00 00 ?? 01 }
// HTTP/2 RST_STREAM frame header: type=0x03 with payload=4
$h2_rst_frame = { 00 00 04 03 00 }
// Python h2 library usage (hyper-h2) typical in PoC tools
$hyper_h2 = "import h2" ascii
$h2_connection = "H2Connection" ascii
condition:
(
($mplx_ref or $spurge_ref or $stream_ref)
or
($cve_str and $version_target)
or
($hyper_h2 and $h2_connection and $h2_rst_frame)
)
}
---
## Plantilla de Evento MISP
Guárdelo como `misp_cve_2026_23918.json` e impórtelo a través de MISP → Events → Import.
> Reemplace los UUIDs de marcador de posición con UUID4 recién generados antes de importar.```json
{
"Event": {
"uuid": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
"info": "CVE-2026-23918 Apache mod_http2 Double-Free — Remote DoS and possible RCE",
"threat_level_id": "2",
"analysis": "2",
"date": "2026-05-04",
"Attribute": [
{
"type": "vulnerability",
"category": "External analysis",
"to_ids": false,
"uuid": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
"comment": "CVE identifier",
"value": "CVE-2026-23918"
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "c3d4e5f6-a7b8-9012-cdef-012345678902",
"comment": "Vulnerability description",
"value": "Double-free in Apache HTTP Server 2.4.66 mod_http2 h2_mplx.c stream cleanup path. Triggered by HTTP/2 HEADERS frame immediately followed by RST_STREAM with non-zero error code before stream registration. Results in DoS (confirmed in-wild) or RCE (lab-demonstrated) in multi-threaded MPM configurations."
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "d4e5f6a7-b8c9-0123-defa-123456789003",
"comment": "Affected component",
"value": "Apache HTTP Server 2.4.66, mod_http2 module, h2_mplx.c — multi-threaded MPM only (event, worker). MPM prefork is NOT affected."
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "e5f6a7b8-c9d0-1234-efab-234567890104",
"comment": "RCE precondition",
"value": "RCE requires APR mmap allocator (default on Debian/Ubuntu and official Apache Docker images). Scoreboard at fixed address bypasses ASLR for practical exploitation."
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "f6a7b8c9-d0e1-2345-fabc-345678901205",
"comment": "Fix commit — r1930444",
"value": "https://svn.apache.org/viewvc?view=revision&revision=1930444"
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "a7b8c9d0-e1f2-3456-abcd-456789012306",
"comment": "Fix commit — r1930796",
"value": "https://svn.apache.org/viewvc?view=revision&revision=1930796"
},
{
"type": "text",
"category": "Other",
"to_ids": true,
"uuid": "b8c9d0e1-f2a3-4567-bcde-567890123407",
"comment": "IoC: HTTP/2 frame trigger sequence",
"value": "HTTP/2 HEADERS frame (type=0x01) immediately followed by RST_STREAM (type=0x03) with non-zero error code, same stream ID, before multiplexer stream registration"
},
{
"type": "text",
"category": "Other",
"to_ids": true,
"uuid": "c9d0e1f2-a3b4-5678-cdef-678901234508",
"comment": "IoC: RST_STREAM frame bytes (raw)",
"value": "00 00 04 03 00 [stream_id 4 bytes] [non-zero error code 4 bytes]"
},
{
"type": "text",
"category": "Other",
"to_ids": true,
"uuid": "d0e1f2a3-b4c5-6789-defa-789012345609",
"comment": "IoC: Server response header (vulnerable version)",
"value": "Server: Apache/2.4.66"
},
{
"type": "text",
"category": "Other",
"to_ids": true,
"uuid": "e1f2a3b4-c5d6-7890-efab-890123456710",
"comment": "Exploitation status",
"value": "DoS exploitation confirmed in the wild. RCE demonstrated in lab conditions; widespread weaponization anticipated."
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "f2a3b4c5-d6e7-8901-fabc-901234567811",
"comment": "Immediate mitigation",
"value": "Disable mod_http2: remove 'Protocols h2 h2c' from Apache config and restart. Or switch to MPM prefork. Definitive fix: upgrade to Apache HTTP Server 2.4.67."
},
{
"type": "url",
"category": "External analysis",
"to_ids": false,
"uuid": "a3b4c5d6-e7f8-9012-abcd-012345678912",
"comment": "Apache official advisory",
"value": "https://httpd.apache.org/security/vulnerabilities_24.html"
},
{
"type": "url",
"category": "External analysis",
"to_ids": false,
"uuid": "b4c5d6e7-f8a9-0123-bcde-123456789013",
"comment": "oss-security disclosure",
"value": "https://seclists.org/oss-sec/2026/q2/387"
}
],
"Object": [
{
"name": "vulnerability",
"meta-category": "vulnerability",
"Attribute": [
{
"type": "vulnerability",
"object_relation": "id",
"value": "CVE-2026-23918"
},
{
"type": "cvss-score",
"object_relation": "cvss-score",
"value": "8.8"
},
{
"type": "text",
"object_relation": "summary",
"value": "Apache mod_http2 double-free via HTTP/2 early reset — remote DoS and possible RCE"
}
]
}
]
}
}
| Versión | Estado | Acción |
|---|---|---|
| 2.4.67 | Parcheado | Versión objetivo |
| 2.4.66 | Vulnerable | Actualizar inmediatamente |
| 2.4.65 y anteriores | No afectado por este error específico | Puede tener otros CVE conocidos — revisar aviso |
Comandos de actualización por distribución:
| Distribución | Comando |
|---|---|
| Ubuntu / Debian | sudo apt-get update && sudo apt-get upgrade apache2 |
| RHEL / Rocky / AlmaLinux | sudo dnf update httpd |
| Amazon Linux | sudo dnf update httpd |
| SUSE / openSUSE | sudo zypper update apache2 |
| Arch Linux | sudo pacman -Syu |
Después de actualizar, verificar:```bash apache2 -v # or httpd -v
### Otras CVEs corregidas en 2.4.67
La versión 2.4.67 corrige cinco CVEs. Las dos más significativas junto a CVE-2026-23918 son:
- **CVE-2026-24072** — Escalada de privilegios mediante el manejo de scripts CGI en Windows (afecta solo a implementaciones Windows)
- **CVE-2026-24081** — La evaluación de expresiones de `mod_rewrite` permite que los autores de `.htaccess` lean archivos arbitrarios como el usuario httpd (afecta a 2.4.66 y anteriores, reportado el 2026-01-20)
- **CVE-2026-24088** — Desbordamiento de búfer en heap en `mod_proxy_ajp` mediante mensajes AJP manipulados desde un backend AJP malicioso (afecta a 2.4.66 y anteriores)
Actualizar a 2.4.67 soluciona las cinco con una sola acción.
---
## Referencia de IoCs clave
| Indicador | Valor | Confianza | Notas |
|---|---|---|---|
| Versión afectada | `Apache/2.4.66` en la cabecera Server | **Alta** | Solo la presencia indica exposición |
| Tipo de trama HTTP/2 | RST_STREAM (0x03) con código de error distinto de cero | Media | Los errores legítimos de conexión producen lo mismo |
| Patrón de bytes de trama | `00 00 04 03 00` (cabecera RST_STREAM) | Media | Combinado con umbral = alta |
| Umbral de inundación RST | >10 RST_STREAM/código de error distinto de cero desde la misma fuente en 30s | **Alta** | Consistente con herramientas DoS activas |
| SIGABRT en trabajador Apache | señal 6 enviada a PID de `httpd`/`apache2` | **Alta** | Los trabajadores normales no abortan |
| Ejecución de shell por www-data | `execve()` de bash/sh por uid 33 o 48 | **Crítica** | Indica fuertemente RCE |
| Conexión saliente por usuario Apache | `connect()` por uid 33 o 48 a IP externa | **Crítica** | Indica fuertemente reverse shell |
| Creación de archivos web en raíz web | Nuevos `.php`/`.py`/`.sh` escritos bajo `/var/www` | **Alta** | Puede indicar despliegue de web shell |
| Tipo de MPM | `mpm_prefork` | N/A — **no afectado** | Verificar con `apachectl -V \| grep MPM` |
| Precondición de RCE | Asignador de memoria APR mmap | Contextual | Por defecto en Debian/Ubuntu; no en RHEL |
---
*Paquete de detección mantenido según los avisos de seguridad de Apache HTTP Server en [httpd.apache.org/security](https://httpd.apache.org/security/). Si observa variantes de explotación o patrones post-explotación no cubiertos por estas reglas, por favor abra un issue.*