{"cve": "CVE-2026-23918", "updated": 1785012052, "url": "https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0530/", "affected": [{"ecosystem": "Debian:12", "package": "apache2", "affected": null, "fixed": "2.4.67-1~deb12u2", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2026-23918"}, {"ecosystem": "Debian:13", "package": "apache2", "affected": null, "fixed": "2.4.66-1~deb13u2", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2026-23918"}, {"ecosystem": "Debian:14", "package": "apache2", "affected": null, "fixed": "2.4.66-5", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2026-23918"}, {"ecosystem": "Ubuntu:26.04:LTS", "package": "apache2", "affected": null, "fixed": "2.4.66-2ubuntu2.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/UBUNTU-CVE-2026-23918"}, {"ecosystem": "SUSE:Linux Enterprise Server 16.0", "package": "apache2", "affected": null, "fixed": "2.4.66-160000.2.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:22199-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP applications 16.0", "package": "apache2", "affected": null, "fixed": "2.4.66-160000.2.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:22199-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 16.0", "package": "apache2", "affected": null, "fixed": "2.4.66-160000.2.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:22209-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP applications 16.0", "package": "apache2", "affected": null, "fixed": "2.4.66-160000.2.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:22209-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS", "package": "apache2", "affected": null, "fixed": "2.4.66-150400.6.57.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:2686-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS", "package": "apache2", "affected": null, "fixed": "2.4.66-150400.6.57.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:2686-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS", "package": "apache2", "affected": null, "fixed": "2.4.66-150400.6.57.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:2686-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS", "package": "apache2", "affected": null, "fixed": "2.4.66-150400.6.57.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:2686-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 15 SP4-LTSS", "package": "apache2", "affected": null, "fixed": "2.4.66-150400.6.57.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:2686-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 15 SP5-LTSS", "package": "apache2", "affected": null, "fixed": "2.4.66-150400.6.57.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:2686-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 15 SP4", "package": "apache2", "affected": null, "fixed": "2.4.66-150400.6.57.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:2686-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 15 SP5", "package": "apache2", "affected": null, "fixed": "2.4.66-150400.6.57.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:2686-1"}, {"ecosystem": "openSUSE:Tumbleweed", "package": "apache2", "affected": null, "fixed": "2.4.67-1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2026:10785-1"}, {"ecosystem": "openSUSE:Leap 16.0", "package": "apache2", "affected": null, "fixed": "2.4.66-160000.2.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2026:21115-1"}, {"ecosystem": "Red Hat:hummingbird:1", "package": "httpd", "affected": null, "fixed": "0:2.4.67-0.1.hum1", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:13938"}]}