# Critical apache CVE-2026-23918 - AIO impacted?

**URL:** <https://help.nextcloud.com/t/critical-apache-cve-2026-23918-aio-impacted/244139>\
**Category:** 🏷️ General\
**Tags:** security, aio\
**Created:** [May 6, 2026, 6:03am UTC](https://help.nextcloud.com/t/critical-apache-cve-2026-23918-aio-impacted/244139 "2026-05-06T06:03:07Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![ChaosMamba](https://help.nextcloud.com/letter_avatar/chaosmamba/32/5_5575768a8748004e209b776fc1b2916d.png) [@ChaosMamba](https://help.nextcloud.com/u/ChaosMamba)\
**Post date:** [May 6, 2026, 6:03am UTC](https://help.nextcloud.com/t/critical-apache-cve-2026-23918-aio-impacted/244139/1 "2026-05-06T06:03:08Z")

</div>

### I have no support/technical question and have seen the support category. (Be aware that direct support questions will be deleted.)

on

### Which general topic do you have

Hi everyone,

I came across a recent security advisory regarding Apache HTTP Server and wanted to check whether Nextcloud All-in-One setups might be impacted.

Apache version 2.4.67 (released May 4, 2026) fixes several vulnerabilities, including a critical issue (CVE-2026-23918, CVSS 8.8) affecting the HTTP/2 implementation. The bug is a double-free memory corruption triggered during an early stream reset in HTTP/2, which can potentially lead to remote code execution. This specifically affects version 2.4.66

Given that Nextcloud All-in-One uses Apache with this exact version and has HTTP/2 support enabled by default in AIO, I’m wondering

- is AIO impcated?
- if yes, when will be the update be released?

Would appreciate any clarification from maintainers or anyone who has looked into this.

Thanks!

---

<div class="post-metadata">

**Author:** ![szaimen](https://help.nextcloud.com/user_avatar/help.nextcloud.com/szaimen/32/63019_2.png) [@szaimen](https://help.nextcloud.com/u/szaimen)\
**Post date:** [May 6, 2026, 8:27am UTC](https://help.nextcloud.com/t/critical-apache-cve-2026-23918-aio-impacted/244139/2 "2026-05-06T08:27:35Z")

</div>

Hey, I just checked this and Apache is not handling h2 in our case as we have a Caddy-server instance in front of Apache that handles the certs and h2 and h3. Also the h2 Apache module is not even enabled.

So the CVE is not applicable in the case of AIO.

---

<div class="post-metadata">

**Author:** ![szaimen](https://help.nextcloud.com/user_avatar/help.nextcloud.com/szaimen/32/63019_2.png) [@szaimen](https://help.nextcloud.com/u/szaimen)\
**Post date:** [May 6, 2026, 8:35am UTC](https://help.nextcloud.com/t/critical-apache-cve-2026-23918-aio-impacted/244139/3 "2026-05-06T08:35:48Z")

</div>



---

<div class="post-metadata">

**Author:** ![ChaosMamba](https://help.nextcloud.com/letter_avatar/chaosmamba/32/5_5575768a8748004e209b776fc1b2916d.png) [@ChaosMamba](https://help.nextcloud.com/u/ChaosMamba)\
**Post date:** [May 6, 2026, 10:34am UTC](https://help.nextcloud.com/t/critical-apache-cve-2026-23918-aio-impacted/244139/4 "2026-05-06T10:34:51Z")

</div>

Hi!

Thank you very much for the checking and clarification!

---

<div class="post-metadata">

**Author:** ![szaimen](https://help.nextcloud.com/user_avatar/help.nextcloud.com/szaimen/32/63019_2.png) [@szaimen](https://help.nextcloud.com/u/szaimen)\
**Post date:** [May 6, 2026, 12:06pm UTC](https://help.nextcloud.com/t/critical-apache-cve-2026-23918-aio-impacted/244139/5 "2026-05-06T12:06:31Z")

</div>

Just FYI: Apache was just updated within AIO to v2.4.67 and is now released with AIO v13.0.2 Beta. Testing and feedback is welcome! See [https://github.com/nextcloud/all-in-one#how-to-switch-the-channel](https://github.com/nextcloud/all-in-one#how-to-switch-the-channel)

---

<div class="post-metadata">

**Author:** ![beedaddy](https://help.nextcloud.com/user_avatar/help.nextcloud.com/beedaddy/32/175_2.png) [@beedaddy](https://help.nextcloud.com/u/beedaddy)\
**Post date:** [May 7, 2026, 11:23am UTC](https://help.nextcloud.com/t/critical-apache-cve-2026-23918-aio-impacted/244139/6 "2026-05-07T11:23:50Z")

</div>

But what about the non-AIO-Image ([docker.io/nextcloud:33](http://docker.io/nextcloud:33))?

---

<div class="post-metadata">

**Author:** ![ernolf](https://help.nextcloud.com/user_avatar/help.nextcloud.com/ernolf/32/77874_2.png) [@ernolf](https://help.nextcloud.com/u/ernolf)\
**Post date:** [May 7, 2026, 12:16pm UTC](https://help.nextcloud.com/t/critical-apache-cve-2026-23918-aio-impacted/244139/7 "2026-05-07T12:16:23Z")

</div>

> [@ChaosMamba](#):
>
> Apache version 2.4.67 (released May 4, 2026) fixes several vulnerabilities, including a critical issue (CVE-2026-23918, CVSS 8.8) affecting the HTTP/2 implementation.

By the way, Ubuntu users with bare-metal installations will not be offered the new version. Anyone who wants to receive the latest security patches immediately—which is, of course, highly recommended for obvious reasons—should use [Ondřej Surý’s PPA for Apache2](https://launchpad.net/~ondrej/+archive/ubuntu/apache2/).

The new version was available online the very next day (May 5).

Here is how to add that ppa to your system:

```sh
sudo LC_ALL=C.UTF-8 add-apt-repository ppa:ondrej/apache2
sudo apt update

```

h.t.h.

* * *

ernolf

---

<div class="post-metadata">

**Author:** ![bb77](https://help.nextcloud.com/letter_avatar/bb77/32/5_5575768a8748004e209b776fc1b2916d.png) [@bb77](https://help.nextcloud.com/u/bb77)\
**Post date:** [May 7, 2026, 12:32pm UTC](https://help.nextcloud.com/t/critical-apache-cve-2026-23918-aio-impacted/244139/8 "2026-05-07T12:32:16Z")

</div>

Ubuntu 26.04 received a fix. All other Ubuntu releases are not affected because they use older versions of Apache, and CVE-2026-23918 only affects version 2.4.66 specifically.

See here: [CVE-2026-23918 | Ubuntu](https://ubuntu.com/security/CVE-2026-23918).

…and here: [Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project](https://httpd.apache.org/security/vulnerabilities_24.html)

But yeah, I’m using the PPA as well, and the fix was made available quickly. 🙂

---

<div class="post-metadata">

**Author:** ![beedaddy](https://help.nextcloud.com/user_avatar/help.nextcloud.com/beedaddy/32/175_2.png) [@beedaddy](https://help.nextcloud.com/u/beedaddy)\
**Post date:** [May 7, 2026, 12:38pm UTC](https://help.nextcloud.com/t/critical-apache-cve-2026-23918-aio-impacted/244139/9 "2026-05-07T12:38:41Z")

</div>

So, if I understood it correctly:

- AIO-Image ✅
- Ubuntu 24.04 ✅
- Apache based non-AIO-Image ([docker.io/nextcloud:33](http://docker.io/nextcloud:33)) ⁉  
(uses Apache 2.4.66)

---

<div class="post-metadata">

**Author:** ![bb77](https://help.nextcloud.com/letter_avatar/bb77/32/5_5575768a8748004e209b776fc1b2916d.png) [@bb77](https://help.nextcloud.com/u/bb77)\
**Post date:** [May 7, 2026, 12:45pm UTC](https://help.nextcloud.com/t/critical-apache-cve-2026-23918-aio-impacted/244139/10 "2026-05-07T12:45:21Z")

</div>

> [@beedaddy](#):
>
> - AIO-Image ✅
> - Ubuntu 24.04 ✅

Yes.

I’m not sure about the Apache Docker image, though. Perhaps you could “docker exec” into the container to check which version is running. As far as I know, the Apache image is Debian-based. Here a link to the Debian Security Tracker for reference: [CVE-2026-23918](https://security-tracker.debian.org/tracker/CVE-2026-23918).

---

<div class="post-metadata">

**Author:** ![SysKeeper](https://help.nextcloud.com/letter_avatar/syskeeper/32/5_5575768a8748004e209b776fc1b2916d.png) [@SysKeeper](https://help.nextcloud.com/u/SysKeeper)\
**Post date:** [May 7, 2026, 12:47pm UTC](https://help.nextcloud.com/t/critical-apache-cve-2026-23918-aio-impacted/244139/11 "2026-05-07T12:47:07Z")

</div>

> [@ernolf](#):
>
> By the way, Ubuntu users with bare-metal installations will not be offered the new version.

Most of the time these are backported by the distro…

---

<div class="post-metadata">

**Author:** ![bb77](https://help.nextcloud.com/letter_avatar/bb77/32/5_5575768a8748004e209b776fc1b2916d.png) [@bb77](https://help.nextcloud.com/u/bb77)\
**Post date:** [May 7, 2026, 1:00pm UTC](https://help.nextcloud.com/t/critical-apache-cve-2026-23918-aio-impacted/244139/12 "2026-05-07T13:00:16Z")

</div>

Yes, on Ubuntu, software is usually never updated to new upstream versions within the lifetime of a release; instead, security fixes are backported to the current version.

That’s why the apache2 package still carries the version number 2.4.66 on Ubuntu 26.04, even though it received the fix. Those changes are reflected with an additional “ubuntu” version number attached to the upstream version:

Release version: 2.4.66-2 **ubuntu2**  
Fixed Version: 2.4.66-2 **ubuntu2.1**

See also:

> **[apache2 package : Ubuntu](https://launchpad.net/ubuntu/+source/apache2)**

---

<div class="post-metadata">

**Author:** ![beedaddy](https://help.nextcloud.com/user_avatar/help.nextcloud.com/beedaddy/32/175_2.png) [@beedaddy](https://help.nextcloud.com/u/beedaddy)\
**Post date:** [May 7, 2026, 1:13pm UTC](https://help.nextcloud.com/t/critical-apache-cve-2026-23918-aio-impacted/244139/13 "2026-05-07T13:13:27Z")

</div>

Yes, I made `podman exec ...` and `apache -V` tells me: **Apache/2.4.66 (Debian)**

---

<div class="post-metadata">

**Author:** ![bb77](https://help.nextcloud.com/letter_avatar/bb77/32/5_5575768a8748004e209b776fc1b2916d.png) [@bb77](https://help.nextcloud.com/u/bb77)\
**Post date:** [May 7, 2026, 1:41pm UTC](https://help.nextcloud.com/t/critical-apache-cve-2026-23918-aio-impacted/244139/14 "2026-05-07T13:41:30Z")

</div>

What does `apt policy apache2` say?

In a Debian 13 LXC of mine (without third party repos) it looks like this:

```auto
apache2:
  Installed: 2.4.67-1~deb13u2
  Candidate: 2.4.67-1~deb13u2
  Version table:
 *** 2.4.67-1~deb13u2 500
        500 http://security.debian.org trixie-security/main amd64 Packages
        100 /var/lib/dpkg/status
     2.4.66-1~deb13u2 500
        500 http://deb.debian.org/debian trixie/main amd64 Packages

```

And `apache2 -v` says:

```auto
Server version: Apache/2.4.67 (Debian)
Server built: 2026-05-06T09:07:41

```

So your version might still be vulnerable. I don’t have any experience with the Nextcloud Docker images, but perhaps you could update it in place via the following command until a new container image is released:

```bash
apt update && apt --only-upgrade install apache2

```

However, before doing that, you could check whether the HTTP2 module is enabled. If not, this particular flaw cannot be exploited.

There are other CVEs in that version that have been fixed, but as far as I know, they are not quite as critical.

So I’d say, it mainly depends on whether your Nextcloud is exposed to the internet. If not, I probably wouldn’t take any action and would wait for a new container image with the updated package. However, I’m not a security expert, so take this advice with a pinch of salt. 😉

---

<div class="post-metadata">

**Author:** ![beedaddy](https://help.nextcloud.com/user_avatar/help.nextcloud.com/beedaddy/32/175_2.png) [@beedaddy](https://help.nextcloud.com/u/beedaddy)\
**Post date:** [May 7, 2026, 4:13pm UTC](https://help.nextcloud.com/t/critical-apache-cve-2026-23918-aio-impacted/244139/15 "2026-05-07T16:13:06Z")

</div>

> [@bb77](#):
>
> However, before doing that, you could check whether the HTTP2 module is enabled. If not, this particular flaw cannot be exploited.

Indeed, the http2 module is not enabled. Thanks for the hint!

---

<div class="post-metadata">

**Author:** ![szaimen](https://help.nextcloud.com/user_avatar/help.nextcloud.com/szaimen/32/63019_2.png) [@szaimen](https://help.nextcloud.com/u/szaimen)\
**Post date:** [May 15, 2026, 3:20pm UTC](https://help.nextcloud.com/t/critical-apache-cve-2026-23918-aio-impacted/244139/17 "2026-05-15T15:20:45Z")

</div>



---

<div class="post-metadata">

**Author:** ![rakekniven](https://help.nextcloud.com/user_avatar/help.nextcloud.com/rakekniven/32/67096_2.png) [@rakekniven](https://help.nextcloud.com/u/rakekniven)\
**Post date:** [May 25, 2026, 6:00am UTC](https://help.nextcloud.com/t/critical-apache-cve-2026-23918-aio-impacted/244139/18 "2026-05-25T06:00:02Z")

</div>

This topic was automatically closed after 7 days. New replies are no longer allowed.
