This repository provides a proof-of-concept demonstration of CVE-2026-23918, a double-free vulnerability in Apache httpd mod_http2 enabling remote code execution before authentication, complete with a vulnerable test environment setup.
How It Works
You find this GitHub project that shows a flaw in a popular web server software.
You learn how this tool helps demonstrate the issue safely in a test setup.
You create an isolated sandbox with the flawed web server version ready to go.
You start the vulnerable server on your computer, accessible only to you.
You run a quick helper to pinpoint special spots inside the server's memory.
You fire off the demonstration to watch the flaw activate in your safe test.
You peek inside the test server to see if your command left a mark.
Success! You've safely reproduced the security issue and learned from it.
Star Growth
Repurpose is a Pro feature
Generate ready-to-use prompts for X threads, LinkedIn posts, blog posts, YouTube scripts, and more -- with full repo context baked in.
Unlock RepurposeSimilar repos coming soon.