
Règles de détection pour CVE-2026-23918 Apache http2 RCE - Credit: stringa.ai, isec.pl
Publié : 2026-05-04
CVSSv3 : 8.8 (Élevé)
Type : Exécution de code à distance / Déni de service (Double-Free Memory Corruption)
Composant : Serveur HTTP Apache ( chemin de nettoyage des flux)
Serveur HTTP Apache 2.4.66 avec HTTP/2 activé et MPM multi-threadé
mod_http2h2_mplx.cCVE-2026-23918 est une vulnérabilité de corruption mémoire de type double-free dans l'implémentation du protocole HTTP/2 du serveur HTTP Apache 2.4.66, affectant uniquement le chemin de nettoyage des flux du module mod_http2 dans h2_mplx.c. Elle permet à un attaquant distant non authentifié de faire planter les processus workers d'Apache (déni de service) avec une seule connexion TCP et deux trames HTTP/2. Dans des conditions présentes sur les systèmes dérivés de Debian et les images Docker officielles d'Apache, le double-free peut être modelé pour une exécution de code à distance complète.
L'exploitation DoS a été confirmée dans la nature. Des scans Internet à grande échelle ciblant les points de terminaison HTTP/2 ont été observés. L'exploit RCE s'est avéré viable dans des environnements contrôlés, bien qu'il n'y ait aucune preuve d'exploitation publique généralisée pour RCE à l'heure actuelle.
Le MPM prefork n'est pas affecté — la vulnérabilité nécessite une configuration MPM multi-threadé (worker, event ou similaire). CVE-2026-23918 n'affecte que la version 2.4.66 du serveur HTTP Apache.
Attacker opens HTTP/2 connection to Apache 2.4.66 (mod_http2 loaded, multi-threaded MPM) └─ Sends HTTP/2 HEADERS frame on stream N (opens the stream) └─ Immediately sends RST_STREAM on stream N (non-zero error code) └─ Sent BEFORE the multiplexer has registered the stream
Two nghttp2 callbacks fire in sequence: ├─ on_frame_recv_cb (RST received) → calls h2_mplx_c1_client_rst → m_stream_cleanup └─ on_stream_close_cb (stream closed) → calls h2_mplx_c1_client_rst → m_stream_cleanup
Result: same h2_stream pointer pushed onto spurge[] cleanup array TWICE
c1_purge_streams() iterates spurge[] and calls h2_stream_destroy() on each entry: ├─ First call: valid — frees the stream └─ Second call: DOUBLE-FREE — operates on already-freed memory → heap corruption
DoS path (trivial, in the wild): └─ Heap corruption → SIGABRT in worker process → worker dies → service disruption
RCE path (requires mmap allocator — default on Debian/Ubuntu and official Docker): └─ Attacker places fake h2_stream struct at freed virtual address via mmap reuse └─ Points pool cleanup function pointer to system() └─ Uses Apache scoreboard shared memory (fixed address, ASLR-resistant) as payload container └─ c1_purge_streams() executes system() with attacker-controlled argument → RCE
> **Asymétrie clé :** La voie DoS ne nécessite aucune compétence de manipulation du tas et est activement exploitée. La voie RCE est techniquement exigeante mais a été démontrée en laboratoire et sera presque certainement transformée en arme dans un avenir proche compte tenu de l'adresse fixe résistante à l'ASLR du scoreboard.
---
## Architecture de détection
> Cette section explique pourquoi les outils de détection ici diffèrent substantiellement d'un package typique d'escalade de privilèges locaux.
Copy Fail (CVE-2026-31431) était une vulnérabilité **côté hôte, post-accès**. L'attaquant devait déjà être présent sur le système. La détection résidait principalement au niveau des appels système (auditd, Wazuh) avec un scan YARA pour le script PoC sur le disque.
CVE-2026-23918 est une vulnérabilité **côté réseau, pré-accès**. L'exploit arrive sous forme de trames de protocole HTTP/2 sur le réseau avant que le code applicatif ne s'exécute. Cela modifie considérablement la pile de détection :
| Couche | Copy Fail (LPE) | CVE-2026-23918 (RCE) |
|---|---|---|
| **Détection principale** | Règles d'appels système auditd | Règles réseau Suricata |
| **WAF (ModSecurity)** | Limité — ne peut pas voir l'exploit | Pertinent — anomalie + post-exploitation |
| **Auditd** | Détection de base | Détection des conséquences (plantages, post-exploitation) |
| **YARA** | Scanne le script PoC | Scanne les web shells (artefacts post-exploitation) |
| **IDS réseau** | Non applicable | Couche de détection de premier ordre |
| **Inspection TLS** | N/A | Requise pour une couverture complète de Suricata |
La règle empirique : pour une RCE au niveau réseau, travailler de l'extérieur vers l'intérieur (réseau → WAF → hôte). Pour une escalade de privilèges locale, travailler de l'hôte vers l'extérieur.
---
## Limites de la détection
> **Lisez ceci avant de déployer une règle quelconque.**
**1. TLS interrompt la visibilité HTTP/2.**
La plupart des déploiements Apache en production servent du HTTPS. Suricata ne peut pas inspecter le contenu des trames HTTP/2 chiffrées sans que le déchiffrement TLS ne soit configuré. Si votre déploiement Suricata n'a pas accès aux clés de session TLS ou à un miroir de déchiffrement, les règles réseau ci-dessous ne détecteront que :
- HTTP/2 en clair (h2c) — rare en production mais présent dans les environnements internes
- La signature réseau du comportement de la connexion TCP (nombre de connexions, motifs RST au niveau TCP)
Pour les déploiements HTTPS, activez le déchiffrement TLS de Suricata via le paramètre `tls-decrypt` et la journalisation des clés de session, ou reposez-vous plutôt sur les couches WAF (ModSecurity/Coraza) et hôte (auditd/Wazuh).
**2. ModSecurity ne peut pas bloquer le déclencheur de l'exploit.**
La double libération se produit à l'intérieur du parseur de trames HTTP/2, avant qu'une requête HTTP complète ne soit assemblée et transmise à ModSecurity. Le WAF ne voit la requête qu'après la fin de l'analyse de la trame — moment où les dégâts peuvent déjà être faits. ModSecurity dans ce package est utilisé pour la détection d'anomalies, la limitation de débit et la détection post-exploitation, pas comme bloqueur du déclencheur.
**3. MPM prefork n'est pas affecté.**
Si votre déploiement Apache utilise `mpm_prefork_module` (monothreadé), cette vulnérabilité ne s'applique pas. Le bogue ne se manifeste que dans les MPM multithreadés (`mpm_event_module` ou `mpm_worker_module`). Vérifiez avec `apachectl -V | grep MPM` avant de déployer des règles qui produiraient des faux positifs sur les serveurs prefork.
**4. La RCE nécessite l'allocateur mmap.**
La voie RCE (pas la voie DoS) nécessite l'allocateur mmap d'APR, qui est par défaut sur les distributions dérivées de Debian et les images Docker officielles d'Apache. Les déploiements basés sur RHEL/CentOS utilisant jemalloc ou malloc système ont un risque RCE réduit, mais restent entièrement vulnérables au DoS.
**5. Pas encore d'IoC de post-exploitation stables.**
Aucun IoC publié par les fournisseurs pour l'activité post-exploitation n'existe au moment de la rédaction. Les règles YARA et auditd ciblant le comportement post-exploitation sont basées sur des schémas généraux de web shell et d'escalade de privilèges — elles détecteront les conséquences courantes mais pas une charge utile sophistiquée sur mesure.
---
## Atténuation immédiate
Appliquez par ordre de préférence. Chacune est plus perturbatrice que la précédente, mais chacune est plus complète.```bash
# Option 1 (Preferred): Upgrade to 2.4.67
# See Patching & Remediation section below
# Option 2: Disable HTTP/2 in Apache config (no reboot required, restart required)
# In httpd.conf or relevant VirtualHost / site config:
# Remove or comment out: Protocols h2 h2c http/1.1
# Replace with: Protocols http/1.1
# Then:
apachectl configtest && sudo systemctl restart apache2
# Option 3: Switch to MPM prefork (eliminates vulnerability entirely — more disruptive)
sudo a2dismod mpm_event mpm_worker
sudo a2enmod mpm_prefork
apachectl configtest && sudo systemctl restart apache2
# Option 4: Reverse proxy HTTP/2 termination
# If nginx, HAProxy, or a CDN is in front of Apache and terminates HTTP/2,
# Apache only receives HTTP/1.1 — confirm your proxy config explicitly:
# nginx: proxy_http_version 1.1; (already the default for upstream connections)
# HAProxy: use-server-close + http/1.1 on backend bind
# Verify with: curl -v --http2 https://your-origin-directly
Vérifiez votre mitigation : Après avoir désactivé HTTP/2, confirmez avec :
curl -s -o /dev/null -w "%{http_version}" --http2 http://localhost/ # Devrait retourner "1.1", pas "2" apachectl -M | grep http2 # Ne devrait produire aucune sortie
Enregistrez sous cve-2026-23918.rules et référencez depuis suricata.yaml.
Prérequis :
- Suricata 6.0+ pour la prise en charge des mots-clés
http2.frametype/http2.errorcode(Suricata 7.x recommandé)app-layer.protocols.http2.enabled: yesdanssuricata.yaml- Déchiffrement TLS configuré pour la couverture HTTPS (voir Limites de détection ci-dessus)
- Variable
$HTTP_SERVERSdéfinie pour inclure vos hôtes Apache- Les SID ci-dessous sont des exemples — adaptez-les à votre politique SID locale```
alert http2 $EXTERNAL_NET any -> $HTTP_SERVERS any
(msg:"CVE-2026-23918 Apache mod_http2 Double-Free - RST_STREAM with non-zero error code";
flow:established,to_server;
http2.frametype:3;
http2.errorcode:!0;
classtype:web-application-attack;
reference:cve,2026-23918;
sid:9926231801; rev:1;)
alert http2 $EXTERNAL_NET any -> $HTTP_SERVERS any
(msg:"CVE-2026-23918 Apache mod_http2 Double-Free - RST_STREAM flood (active DoS/exploit scan)";
flow:established,to_server;
http2.frametype:3;
http2.errorcode:!0;
threshold: type both, track by_src, count 10, seconds 30;
classtype:denial-of-service;
reference:cve,2026-23918;
sid:9926231802; rev:1;)
alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS [80,8080,8000,8443]
(msg:"CVE-2026-23918 Apache mod_http2 - HTTP/2 RST_STREAM frame detected (cleartext)";
flow:established,to_server;
content:"|00 00 04 03 00|"; depth:5; offset:0;
threshold: type both, track by_src, count 5, seconds 30;
classtype:web-application-attack;
reference:cve,2026-23918;
sid:9926231803; rev:1;)
alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS [80,8080,8000]
(msg:"CVE-2026-23918 Apache mod_http2 - HTTP/2 client preface with rapid RST_STREAM (exploit pattern)";
flow:established,to_server;
content:"PRI * HTTP/2.0|0d 0a 0d 0a|SM|0d 0a 0d 0a|"; depth:24; offset:0;
content:"|00 00 04 03|"; distance:0; within:512;
classtype:web-application-attack;
reference:cve,2026-23918;
sid:9926231804; rev:1;)
alert http $HTTP_SERVERS any -> $EXTERNAL_NET any
(msg:"CVE-2026-23918 Apache 2.4.66 version string in response - vulnerable version exposed";
flow:established,to_client;
http.header; content:"Apache/2.4.66";
classtype:policy-violation;
reference:cve,2026-23918;
sid:9926231805; rev:1;)
alert tcp $HTTP_SERVERS [80,443,8080,8443] -> $EXTERNAL_NET ![$HTTP_PORTS,443,80]
(msg:"CVE-2026-23918 Apache possible post-RCE reverse shell - outbound from web server port";
flow:established,to_server;
classtype:trojan-activity;
reference:cve,2026-23918;
sid:9926231806; rev:1;)
### Notes de réglage
Après un déploiement en mode `alert` pendant 24 à 48 heures, examinez les alertes sur les règles 3 et 4 — les clients HTTP/2 légitimes peuvent déclencher ces règles dans des environnements à fort trafic. Si la règle 1 (couche applicative) capture suffisamment de signaux, les règles 3 et 4 peuvent être rétrogradées ou supprimées.
Pour les déploiements Suricata avec des limites `stream-depth`, assurez-vous que le motif de préface HTTP/2 de la règle 4 se trouve dans la fenêtre d'inspection.
---
## Configuration ModSecurity / Coraza
> **Prérequis :**
> - ModSecurity 2.x (`libapache2-mod-security2`) ou [Coraza](https://coraza.io/) (successeur compatible, activement maintenu)
> - OWASP Core Rule Set (CRS) 4.x recommandé : [coreruleset.org/installation](https://coreruleset.org/installation/)
> - `SecRuleEngine On` (ou `DetectionOnly` pour un mode de journalisation uniquement lors du réglage initial)
### Pourquoi ModSecurity est pertinent ici (mais pas suffisant)
Comme indiqué dans la section Limitations de détection, ModSecurity ne peut pas intercepter le déclencheur de double libération car l'exploit opère au niveau de la couche de trames HTTP/2. Cependant, ModSecurity offre trois niveaux de valeur significatifs pour cette CVE :
1. **Limitation de débit** — ralentit le balayage DoS automatisé et augmente le coût du forçage brut du heap spray pour RCE
2. **Détection post-exploitation** — si la RCE est réalisée, l'attaquant tentera de déployer un web shell ou d'exécuter des commandes ; ModSecurity peut détecter les deux
3. **Score d'anomalie OWASP CRS** — les en-têtes malformés et les schémas de connexion associés à l'exploitation peuvent obtenir un score anormal sous le niveau de paranoïa 2+ du CRS
### Renforcement de la configuration Apache (appliquer en parallèle de ModSecurity)
Ajouter à `httpd.conf` ou à un fichier d'inclusion. Ce sont des directives Apache, pas des règles ModSecurity, mais elles réduisent la surface d'attaque HTTP/2 :```apache
# ============================================================
# CVE-2026-23918 Apache HTTP/2 Hardening Directives
# ============================================================
# Limit concurrent streams per HTTP/2 session.
# The exploit typically uses 1 stream, but limiting sessions
# reduces the rate at which a single client can attempt the trigger.
H2MaxSessionRequests 100
# Restrict H2 stream push (unused surface, reduce complexity)
H2Push Off
# Suppress version information in Server headers.
# Prevents trivial identification of vulnerable 2.4.66 instances.
ServerTokens Prod
ServerSignature Off
# Constrain HTTP/2 window size — reduces memory available for heap spray
H2WindowSize 65535
# If HTTP/2 is not required at all:
# Protocols http/1.1
Enregistrez-les dans votre fichier de règles personnalisées ModSecurity (par exemple, /etc/modsecurity/cve-2026-23918.conf) :```apache
SecAction
"id:9923918001,
phase:1,
nolog,
pass,
initcol:ip=%{REMOTE_ADDR},
setvar:ip.http2_requests=+1,
expirevar:ip.http2_requests=60"
SecRule ip:http2_requests "@gt 30"
"id:9923918002,
phase:1,
deny,
status:429,
log,
msg:'CVE-2026-23918: Rate limit exceeded - possible DoS/exploit scan',
tag:'CVE-2026-23918',
tag:'OWASP_CRS/DoS',
severity:'CRITICAL'"
SecAction
"id:9923918003,
phase:1,
nolog,
pass,
initcol:ip=%{REMOTE_ADDR}"
SecRule RESPONSE_STATUS "@rx ^(4|5)[0-9]{2}"
"id:9923918004,
phase:5,
nolog,
pass,
setvar:ip.error_count=+1,
expirevar:ip.error_count=120"
SecRule ip:error_count "@gt 20"
"id:9923918005,
phase:1,
log,
pass,
msg:'CVE-2026-23918: Elevated error rate from source IP - possible exploit scanning',
tag:'CVE-2026-23918',
severity:'WARNING'"
SecRule REQUEST_BODY
"@rx (?:system|exec|passthru|shell_exec|popen|proc_open)\s*(\s*(?:$_(?:GET|POST|REQUEST|COOKIE)|base64_decode)"
"id:9923918010,
phase:2,
deny,
status:403,
log,
msg:'CVE-2026-23918: Possible web shell command execution in POST body',
tag:'CVE-2026-23918',
tag:'WEBSHELL',
severity:'CRITICAL'"
SecRule ARGS
"@rx (?:(?:^|[;&|`])\s*(?:id|whoami|uname|cat\s+/etc|ls\s+/|pwd|wget\s+http|curl\s+http|bash\s+-[ci]|nc\s+-[el]|python[23]?\s+-c|perl\s+-e|ruby\s+-e))"
"id:9923918011,
phase:2,
deny,
status:403,
log,
msg:'CVE-2026-23918: OS command injection pattern in request arguments - possible post-exploit web shell',
tag:'CVE-2026-23918',
tag:'WEBSHELL',
severity:'CRITICAL'"
SecRule FILES_TMPNAMES "@inspectFile /etc/modsecurity/util/php-filter.pm"
"id:9923918012,
phase:2,
log,
deny,
status:403,
msg:'CVE-2026-23918: PHP code detected in file upload - possible web shell deployment',
tag:'CVE-2026-23918',
tag:'WEBSHELL',
severity:'CRITICAL'"
SecRule REQUEST_BODY|ARGS
"@rx (?:bash\s+-i\s+>&?\s*/dev/tcp|/dev/tcp/[0-9]{1,3}.[0-9]{1,3}|nc\s+(?:-e|-c)\s+/bin/(?:bash|sh)|python[23]?\s+-c\s+['"]import\s+socket)"
"id:9923918013,
phase:2,
deny,
status:403,
log,
msg:'CVE-2026-23918: Reverse shell pattern in request - possible post-exploit activity',
tag:'CVE-2026-23918',
tag:'REVERSE_SHELL',
severity:'CRITICAL'"
### Recommandation de réglage CRS OWASP
Pour le meilleur signal d’anomalie sans trop de faux positifs, déployez CRS au niveau de paranoïa 2 avec le score d’anomalie activé. Le comportement déclencheur de connexion (HTTP/2 malformé entraînant des erreurs de repli HTTP/1.x, des réinitialisations répétées) accumulera un score d’anomalie sous les règles CRS 920xxx et 921xxx et pourra dépasser le seuil par défaut `inbound_anomaly_score_threshold` de 5, générant des alertes sans règles personnalisées.
---
## Règles Auditd
Enregistrer sous `/etc/audit/rules.d/cve-2026-23918.rules`
Recharger avec : `sudo augenrules --load`
> **Principe de conception :** Le déclencheur de l’exploit résidant dans la couche d’analyse HTTP/2 du noyau/réseau, auditd ne peut pas capturer le déclencheur lui-même. Ces règles détectent :
> 1. Le **résultat** de l’exploitation DoS (signaux de crash du worker Apache)
> 2. L’**activité post-exploitation** en cas de RCE (exécution de shell, écritures de fichiers, connexions sortantes par l’utilisateur Apache)```bash
## ============================================================
## CVE-2026-23918 Apache HTTP/2 Double-Free — Auditd Rules
## ============================================================
## These rules detect the CONSEQUENCES of exploitation, not the
## trigger. The trigger is a network protocol event and is
## detected by Suricata. These rules catch:
## 1. Apache worker process crashes (DoS outcome)
## 2. Shell execution by the web server user (RCE outcome)
## 3. Web root file creation (web shell deployment)
## 4. Outbound network connections by web server process (reverse shell)
##
## Distribution notes for UID values:
## - Debian/Ubuntu: www-data = uid 33
## - RHEL/Rocky/CentOS: apache = uid 48
## Adjust -F uid= values for your distribution. Use `id www-data`
## or `id apache` to confirm the UID on your systems.
## ============================================================
## --- Apache worker SIGABRT detection (DoS exploitation outcome) ---
## A double-free that reaches the crash path generates SIGABRT (signal 6).
## Monitoring kill() syscalls with a1=6 (SIGABRT) targets abnormal process
## termination, which Apache itself triggers on double-free detection.
## Correlate with Apache error log entries (child exited with signal 6).
-a always,exit -F arch=b64 -S kill -F a1=6 -k cve_2026_23918_sigabrt
-a always,exit -F arch=b32 -S kill -F a1=6 -k cve_2026_23918_sigabrt
## --- SIGSEGV monitoring (alternative crash path) ---
## Depending on heap state, the double-free may produce a SIGSEGV (signal 11)
## rather than SIGABRT. Both are abnormal for production Apache workers.
-a always,exit -F arch=b64 -S kill -F a1=11 -k cve_2026_23918_sigsegv
-a always,exit -F arch=b32 -S kill -F a1=11 -k cve_2026_23918_sigsegv
## --- Shell execution by web server user (RCE outcome - Debian/Ubuntu) ---
## If RCE is achieved via the mmap allocator path, the attacker's payload
## runs as the Apache worker user (www-data on Debian/Ubuntu, uid=33).
## Legitimate Apache does not exec() a shell. Any execve() of bash/sh/dash
## by www-data is anomalous and warrants immediate investigation.
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/bin/bash -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/bin/sh -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/bin/dash -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/usr/bin/python3 -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/usr/bin/perl -k cve_2026_23918_rce_shell_deb
## --- Shell execution by web server user (RCE outcome - RHEL/Rocky, uid=48) ---
-a always,exit -F arch=b64 -S execve -F uid=48 -F exe=/bin/bash -k cve_2026_23918_rce_shell_rhel
-a always,exit -F arch=b64 -S execve -F uid=48 -F exe=/bin/sh -k cve_2026_23918_rce_shell_rhel
## --- Web root file creation (web shell deployment) ---
## Post-RCE, the most common next step is writing a persistent web shell.
## Monitor web root directories for new file creation and write operations.
## Adjust paths for your DocumentRoot configuration.
-w /var/www/html -p wa -k cve_2026_23918_webroot_write
-w /var/www -p wa -k cve_2026_23918_webroot_write
-w /srv/www -p wa -k cve_2026_23918_webroot_write
-w /usr/share/apache2/default-site -p wa -k cve_2026_23918_webroot_write
## --- Outbound network connections by web server user (reverse shell) ---
## Apache workers do not normally initiate outbound TCP connections.
## connect() syscalls by www-data/apache indicate post-exploitation activity.
-a always,exit -F arch=b64 -S connect -F uid=33 -k cve_2026_23918_apache_outbound_deb
-a always,exit -F arch=b64 -S connect -F uid=48 -k cve_2026_23918_apache_outbound_rhel
## --- Apache config and module modification (persistence) ---
## An attacker with RCE may attempt to persist by modifying Apache config
## or dropping a malicious module. Watch for writes to config directories.
-w /etc/apache2 -p wa -k cve_2026_23918_apache_config
-w /etc/httpd -p wa -k cve_2026_23918_apache_config
-w /etc/apache2/mods-enabled -p wa -k cve_2026_23918_apache_mods
Après le déploiement, utilisez cette commande en une ligne ausearch pour vérifier les séquences crash-puis-shell :```bash
sudo ausearch -k cve_2026_23918_sigabrt
-k cve_2026_23918_rce_shell_deb
-k cve_2026_23918_rce_shell_rhel
-k cve_2026_23918_webroot_write
--start yesterday -i
sudo ausearch -k cve_2026_23918_rce_shell_deb --start today -i | grep -A5 "exe="
---
## Règles Wazuh
Enregistrer en tant que fichier de règles personnalisées (par exemple, `/var/ossec/etc/rules/local_rules.xml`).
> **Prérequis :**
> - Les règles Auditd ci-dessus déployées et le décodeur Auditd de Wazuh actif
> - Le journal d'erreurs Apache (`/var/log/apache2/error.log` ou `/var/log/httpd/error_log`) ajouté aux fichiers surveillés par Wazuh
> - Le journal d'accès Apache surveillé pour les motifs d'erreur de connexion HTTP/2```xml
<!-- ==============================================================
CVE-2026-23918 Apache HTTP/2 Double-Free — Wazuh Rules
Requires:
- auditd rules from cve-2026-23918.rules deployed
- Apache error log monitored by Wazuh agent
============================================================== -->
<!-- Level 10: Apache worker crash signal (SIGABRT) detected via auditd -->
<rule id="113001" level="10">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_sigabrt</field>
<description>CVE-2026-23918: SIGABRT sent to process — possible Apache worker double-free crash (DoS exploitation)</description>
<group>cve,denial_of_service,apache,http2,</group>
</rule>
<!-- Level 10: SIGSEGV variant crash path -->
<rule id="113002" level="10">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_sigsegv</field>
<description>CVE-2026-23918: SIGSEGV sent to process — possible Apache worker memory corruption crash</description>
<group>cve,denial_of_service,apache,http2,</group>
</rule>
<!-- Level 14 CRITICAL: Multiple worker crashes in short window — active DoS -->
<rule id="113003" level="14" frequency="3" timeframe="60">
<if_matched_sid>113001</if_matched_sid>
<description>CVE-2026-23918 CRITICAL: Multiple Apache worker SIGABRT crashes within 60 seconds — active DoS exploitation in progress</description>
<group>cve,denial_of_service,apache,http2,high_confidence,</group>
</rule>
<!-- Level 15 CRITICAL: Shell execution by web server user — RCE achieved -->
<rule id="113004" level="15">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_rce_shell_deb|cve_2026_23918_rce_shell_rhel</field>
<description>CVE-2026-23918 CRITICAL: Shell executed by web server user (www-data/apache) — RCE likely achieved, immediate incident response required</description>
<group>cve,rce,privilege_escalation,apache,http2,high_confidence,</group>
</rule>
<!-- Level 14 CRITICAL: Web shell written to web root -->
<rule id="113005" level="14">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_webroot_write</field>
<description>CVE-2026-23918: File written to web root directory — possible web shell deployment post-RCE</description>
<group>cve,rce,webshell,apache,</group>
</rule>
<!-- Level 13 CRITICAL: Outbound connection by Apache worker process -->
<rule id="113006" level="13">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_apache_outbound_deb|cve_2026_23918_apache_outbound_rhel</field>
<description>CVE-2026-23918: Outbound TCP connection by web server user — possible reverse shell post-RCE</description>
<group>cve,rce,reverse_shell,apache,</group>
</rule>
<!-- Level 14: RCE shell followed by outbound connection (reverse shell confirmed) -->
<rule id="113007" level="14">
<if_matched_sid>113004</if_matched_sid>
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_apache_outbound_deb|cve_2026_23918_apache_outbound_rhel</field>
<description>CVE-2026-23918 CRITICAL: Shell execution AND outbound connection by web server user — reverse shell active</description>
<group>cve,rce,reverse_shell,apache,high_confidence,</group>
</rule>
<!-- Level 12: Apache config modified (persistence attempt) -->
<rule id="113008" level="12">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_apache_config|cve_2026_23918_apache_mods</field>
<description>CVE-2026-23918: Apache config or module directory modified — possible attacker persistence attempt</description>
<group>cve,rce,persistence,apache,</group>
</rule>
<!-- Level 10: Apache error log — child process crash (log-based correlation) -->
<!-- Requires Apache error log monitored by Wazuh, decoded via apache decoder -->
<rule id="113009" level="10">
<decoded_as>apache-errorlog</decoded_as>
<match>child pid \d+ exit signal Aborted|child process \d+ still did not exit|segmentation fault</match>
<description>CVE-2026-23918: Apache child process crash in error log — possible double-free DoS exploitation</description>
<group>cve,denial_of_service,apache,http2,</group>
</rule>
<!-- Level 13: Multiple Apache child crashes in error log + auditd SIGABRT (high confidence) -->
<rule id="113010" level="13">
<if_matched_sid>113009</if_matched_sid>
<if_matched_sid>113001</if_matched_sid>
<description>CVE-2026-23918: Apache error log crash + auditd SIGABRT — high-confidence active DoS, investigate immediately</description>
<group>cve,denial_of_service,apache,http2,high_confidence,</group>
</rule>
Enregistrer sous cve_2026_23918.yar
Note importante sur le périmètre : Contrairement à Copy Fail (CVE-2026-31431), YARA ne peut pas détecter le déclencheur d'exploitation de cette vulnérabilité. Le déclencheur est constitué de deux trames HTTP/2 brutes envoyées sur une connexion réseau — il n'y a ni script ni fichier à analyser. Les règles YARA ci-dessous ciblent :
- Les shells web post-exploitation qui peuvent être déployés après une RCE réussie
- Les one-liners de reverse shell et les charges utiles encodées dans les fichiers accessibles via le web
- L'outil d'exploitation lui-même s'il est présent sur un hôte pivot ou un serveur de staging de l'attaquant
Périmètre d'analyse recommandé : les répertoires racine web (
/var/www/,/srv/www/), les répertoires temporaires Apache (/tmp/,/var/tmp/), et les fichiers récemment créés appartenant àwww-dataouapache.```yara rule CVE_2026_23918_PostExploit_PHP_WebShell { meta: description = "Post-exploitation PHP web shell — possible CVE-2026-23918 outcome" author = "Detection Engineering" reference = "https://insomnisec.com/posts/2026-05-05-cve-2026-23918-apache-http2-rce_v2/" cve = "CVE-2026-23918" date = "2026-05-08" severity = "Critical" note = "Not specific to CVE-2026-23918 trigger — detects likely post-exploitation artifacts"
strings:
$php_open = "<?php" ascii nocase
$php_short = "<?" ascii nocase
// OS command execution functions
$sys = "system(" ascii nocase
$exec = "exec(" ascii nocase
$passthru = "passthru(" ascii nocase
$shell_exec = "shell_exec(" ascii nocase
$popen = "popen(" ascii nocase
$proc_open = "proc_open(" ascii nocase
// Parameter sourcing — required for command injection
$get_param = "$_GET[" ascii
$post_param = "$_POST[" ascii
$req_param = "$_REQUEST[" ascii
$cookie_param = "$_COOKIE[" ascii
$server_param = "$_SERVER[" ascii
// Obfuscation patterns common in web shells
$b64decode = "base64_decode(" ascii nocase
$str_rot13 = "str_rot13(" ascii nocase
$gzinflate = "gzinflate(" ascii nocase
$eval_call = "eval(" ascii nocase
// Common web shell capability strings
$phpinfo = "phpinfo()" ascii nocase
$file_put = "file_put_contents(" ascii nocase
condition:
filesize < 512KB and
(
// Classic command web shell: PHP + execution function + parameter input
($php_open or $php_short) and
any of ($sys, $exec, $passthru, $shell_exec, $popen, $proc_open) and
any of ($get_param, $post_param, $req_param, $cookie_param)
)
or
(
// Obfuscated web shell: eval + decode chain
($php_open or $php_short) and
$eval_call and
any of ($b64decode, $str_rot13, $gzinflate)
)
}
rule CVE_2026_23918_PostExploit_ReverseShell_InFile { meta: description = "Reverse shell one-liner in web-accessible file — possible post-RCE persistence" author = "Detection Engineering" cve = "CVE-2026-23918" date = "2026-05-08" severity = "Critical" note = "Scan web directories and /tmp; may also appear in crontabs and rc.local"
strings:
// Bash TCP reverse shell
$bash_tcp = "/dev/tcp/" ascii
$bash_rev = "bash -i >&" ascii nocase
// Netcat reverse shell
$nc_e = "nc -e /bin/" ascii nocase
$nc_c = "nc -c /bin/" ascii nocase
$ncat_e = "ncat -e /bin/" ascii nocase
// Python reverse shell
$py_socket = "import socket,subprocess" ascii
$py_pty = "import pty;pty.spawn" ascii
// Perl reverse shell
$perl_rev = "perl -e 'use Socket" ascii
// Common reverse shell via curl/wget pipe to bash
$curl_bash = "curl http" ascii
$wget_bash = "wget -O- http" ascii
$bash_pipe = "|bash" ascii
condition:
filesize < 1MB and
(
($bash_tcp and $bash_rev)
or ($nc_e or $nc_c or $ncat_e)
or ($py_socket and $py_pty)
or $perl_rev
or ($curl_bash and $bash_pipe)
or ($wget_bash and $bash_pipe)
)
}
rule CVE_2026_23918_ExploitTool_Artifacts { meta: description = "CVE-2026-23918 exploit tool artifacts — for scanning attacker staging hosts or memory dumps" author = "Detection Engineering" reference = "https://hadrian.io/blog/cve-2026-23918-apache-http-server-double-free-rce-in-http-2-implementation" cve = "CVE-2026-23918" date = "2026-05-08" severity = "High" note = "Matches known PoC tool strings — not expected in production Apache environments"
strings:
// h2_mplx.c specific identifier from public PoC analysis
$mplx_ref = "h2_mplx_c1_client_rst" ascii
$spurge_ref = "c1_purge_streams" ascii
$stream_ref = "h2_stream_destroy" ascii
// CVE reference strings that appear in PoC tools
$cve_str = "CVE-2026-23918" ascii
$version_target = "Apache/2.4.66" ascii
// HTTP/2 HEADERS + RST_STREAM frame bytes (common in PoC HTTP/2 libraries)
// HTTP/2 HEADERS frame header: type=0x01
$h2_headers_frame = { 00 00 ?? 01 }
// HTTP/2 RST_STREAM frame header: type=0x03 with payload=4
$h2_rst_frame = { 00 00 04 03 00 }
// Python h2 library usage (hyper-h2) typical in PoC tools
$hyper_h2 = "import h2" ascii
$h2_connection = "H2Connection" ascii
condition:
(
($mplx_ref or $spurge_ref or $stream_ref)
or
($cve_str and $version_target)
or
($hyper_h2 and $h2_connection and $h2_rst_frame)
)
}
---
## Modèle d'événement MISP
Enregistrez sous `misp_cve_2026_23918.json` et importez via MISP → Événements → Import.
> Remplacez les UUIDs factices par des UUID4 fraîchement générés avant l'importation.```json
{
"Event": {
"uuid": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
"info": "CVE-2026-23918 Apache mod_http2 Double-Free — Remote DoS and possible RCE",
"threat_level_id": "2",
"analysis": "2",
"date": "2026-05-04",
"Attribute": [
{
"type": "vulnerability",
"category": "External analysis",
"to_ids": false,
"uuid": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
"comment": "CVE identifier",
"value": "CVE-2026-23918"
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "c3d4e5f6-a7b8-9012-cdef-012345678902",
"comment": "Vulnerability description",
"value": "Double-free in Apache HTTP Server 2.4.66 mod_http2 h2_mplx.c stream cleanup path. Triggered by HTTP/2 HEADERS frame immediately followed by RST_STREAM with non-zero error code before stream registration. Results in DoS (confirmed in-wild) or RCE (lab-demonstrated) in multi-threaded MPM configurations."
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "d4e5f6a7-b8c9-0123-defa-123456789003",
"comment": "Affected component",
"value": "Apache HTTP Server 2.4.66, mod_http2 module, h2_mplx.c — multi-threaded MPM only (event, worker). MPM prefork is NOT affected."
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "e5f6a7b8-c9d0-1234-efab-234567890104",
"comment": "RCE precondition",
"value": "RCE requires APR mmap allocator (default on Debian/Ubuntu and official Apache Docker images). Scoreboard at fixed address bypasses ASLR for practical exploitation."
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "f6a7b8c9-d0e1-2345-fabc-345678901205",
"comment": "Fix commit — r1930444",
"value": "https://svn.apache.org/viewvc?view=revision&revision=1930444"
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "a7b8c9d0-e1f2-3456-abcd-456789012306",
"comment": "Fix commit — r1930796",
"value": "https://svn.apache.org/viewvc?view=revision&revision=1930796"
},
{
"type": "text",
"category": "Other",
"to_ids": true,
"uuid": "b8c9d0e1-f2a3-4567-bcde-567890123407",
"comment": "IoC: HTTP/2 frame trigger sequence",
"value": "HTTP/2 HEADERS frame (type=0x01) immediately followed by RST_STREAM (type=0x03) with non-zero error code, same stream ID, before multiplexer stream registration"
},
{
"type": "text",
"category": "Other",
"to_ids": true,
"uuid": "c9d0e1f2-a3b4-5678-cdef-678901234508",
"comment": "IoC: RST_STREAM frame bytes (raw)",
"value": "00 00 04 03 00 [stream_id 4 bytes] [non-zero error code 4 bytes]"
},
{
"type": "text",
"category": "Other",
"to_ids": true,
"uuid": "d0e1f2a3-b4c5-6789-defa-789012345609",
"comment": "IoC: Server response header (vulnerable version)",
"value": "Server: Apache/2.4.66"
},
{
"type": "text",
"category": "Other",
"to_ids": true,
"uuid": "e1f2a3b4-c5d6-7890-efab-890123456710",
"comment": "Exploitation status",
"value": "DoS exploitation confirmed in the wild. RCE demonstrated in lab conditions; widespread weaponization anticipated."
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "f2a3b4c5-d6e7-8901-fabc-901234567811",
"comment": "Immediate mitigation",
"value": "Disable mod_http2: remove 'Protocols h2 h2c' from Apache config and restart. Or switch to MPM prefork. Definitive fix: upgrade to Apache HTTP Server 2.4.67."
},
{
"type": "url",
"category": "External analysis",
"to_ids": false,
"uuid": "a3b4c5d6-e7f8-9012-abcd-012345678912",
"comment": "Apache official advisory",
"value": "https://httpd.apache.org/security/vulnerabilities_24.html"
},
{
"type": "url",
"category": "External analysis",
"to_ids": false,
"uuid": "b4c5d6e7-f8a9-0123-bcde-123456789013",
"comment": "oss-security disclosure",
"value": "https://seclists.org/oss-sec/2026/q2/387"
}
],
"Object": [
{
"name": "vulnerability",
"meta-category": "vulnerability",
"Attribute": [
{
"type": "vulnerability",
"object_relation": "id",
"value": "CVE-2026-23918"
},
{
"type": "cvss-score",
"object_relation": "cvss-score",
"value": "8.8"
},
{
"type": "text",
"object_relation": "summary",
"value": "Apache mod_http2 double-free via HTTP/2 early reset — remote DoS and possible RCE"
}
]
}
]
}
}
| Version | Statut | Action |
|---|---|---|
| 2.4.67 | Corrigé | Version cible |
| 2.4.66 | Vulnérable | Mettre à niveau immédiatement |
| 2.4.65 et antérieures | Non affecté par ce bogue spécifique | Peut avoir d'autres CVE connus — consulter l'avis |
Commandes de mise à jour par distribution :
| Distribution | Commande |
|---|---|
| Ubuntu / Debian | sudo apt-get update && sudo apt-get upgrade apache2 |
| RHEL / Rocky / AlmaLinux | sudo dnf update httpd |
| Amazon Linux | sudo dnf update httpd |
| SUSE / openSUSE | sudo zypper update apache2 |
| Arch Linux | sudo pacman -Syu |
Après la mise à niveau, vérifiez :```bash apache2 -v # or httpd -v
### Autres CVE corrigées dans 2.4.67
La version 2.4.67 corrige cinq CVE. Les deux plus significatives aux côtés de CVE-2026-23918 sont :
- **CVE-2026-24072** — Escalade de privilèges via la gestion de scripts CGI sur Windows (concerne uniquement les déploiements Windows)
- **CVE-2026-24081** — L'évaluation d'expression de `mod_rewrite` permet aux auteurs de `.htaccess` de lire des fichiers arbitraires en tant qu'utilisateur httpd (concerne 2.4.66 et versions antérieures, signalé le 20/01/2026)
- **CVE-2026-24088** — Débordement de tampon sur le tas dans `mod_proxy_ajp` via des messages AJP conçus provenant d'un backend AJP malveillant (concerne 2.4.66 et versions antérieures)
La mise à niveau vers 2.4.67 corrige les cinq en une seule action.
---
## Référence des IoCs clés
| Indicateur | Valeur | Confiance | Remarques |
|---|---|---|---|
| Version concernée | `Apache/2.4.66` dans l'en-tête Server | **Élevée** | La seule présence indique une exposition |
| Type de trame HTTP/2 | RST_STREAM (0x03) avec code d'erreur non nul | Moyenne | Les erreurs de connexion légitimes produisent la même chose |
| Motif d'octets de trame | `00 00 04 03 00` (en-tête RST_STREAM) | Moyenne | Combiné avec un seuil = élevée |
| Seuil d'inondation RST | >10 RST_STREAM/erreur non nulle de la même source en 30s | **Élevée** | Cohérent avec les outils DoS observés |
| SIGABRT sur un worker Apache | signal 6 envoyé au PID `httpd`/`apache2` | **Élevée** | Les workers normaux ne s'arrêtent pas |
| Exécution de shell par www-data | `execve()` de bash/sh par uid 33 ou 48 | **Critique** | Indique fortement une RCE |
| Connexion sortante par l'utilisateur Apache | `connect()` par uid 33 ou 48 vers une IP externe | **Critique** | Indique fortement un reverse shell |
| Création de fichier web dans la racine web | Nouveaux fichiers `.php`/`.py`/`.sh` écrits sous `/var/www` | **Élevée** | Peut indiquer un déploiement de web shell |
| Type de MPM | `mpm_prefork` | N/A — **non concerné** | Vérifier avec `apachectl -V \| grep MPM` |
| Précondition à la RCE | Allocateur mmap d'APR | Contextuel | Par défaut sur Debian/Ubuntu ; pas par défaut sur RHEL |
---
*Le package de détection est maintenu conformément aux avis de sécurité du serveur HTTP Apache sur [httpd.apache.org/security](https://httpd.apache.org/security/). Si vous observez des variantes d'exploitation ou des schémas post-exploitation non couverts par ces règles, veuillez ouvrir un ticket.*